iOS 17.1 and Later Fix Logic Issue to Improve Network Volume Security
CVE-2023-42836
5.3MEDIUM
Summary
A logic issue has been identified in Apple's operating systems that may enable malicious actors to gain unauthorized access to connected network volumes mounted in a user's home directory. This vulnerability affects multiple versions of iOS, iPadOS, and macOS, highlighting the potential risk to data integrity and user privacy. Users should ensure their devices are updated to the latest versions to mitigate the risk associated with this issue and safeguard their information from potential exploitation.
Affected Version(s)
iOS and iPadOS < 17.1
macOS < 13.6
macOS < 14.1
References
CVSS V3.1
Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved