Apple Addresses Root Privilege Vulnerability in macOS Ventura 13.4, tvOS 16.5, iOS 16.5, and iPadOS 16.5
CVE-2023-32428
Key Information:
- Vendor
Apple
- Vendor
- CVE Published:
- 6 September 2023
Badges
What is CVE-2023-32428?
The vulnerability CVE-2023-32428 in Apple's macOS Ventura 13.4, tvOS 16.5, iOS 16.5, and iPadOS 16.5 allowed an app to gain root privileges, but was fixed with improved file handling in the mentioned updates. The blog by Gergely discussed various security vulnerabilities and releases, including badmalloc (CVE-2023-32428) - a macOS LPE, fs_usage_ng tool release, security of filesystems and file APIs, a Windscribe VPN privilege escalation, hacking ISP CPE equipment, and various other macOS vulnerabilities and bypasses. The blog did not mention any known exploitation of the vulnerabilities by ransomware groups.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
iOS and iPadOS < 16.5
macOS < 13.4
tvOS < 16.5
News Articles
Gergely's hack blog
Gergely's blog about hacking, privacy, and everything else
AUSCERT Week in Review for 29th November 2024 - AUSCERT
Greetings, This week, we had the exciting opportunity to reconnect with our Melbourne community at an AUSCERT member meetup. It was an inspiring space for collaboration, where participants shared experiences,...
References
CVSS V3.1
Timeline
- ๐พ
Exploit known to exist
- ๐ฐ
First article discovered by AusCERT
Vulnerability published
Vulnerability Reserved