Out-of-Bounds Read Vulnerability in Apple Operating Systems
CVE-2023-42862

6.5MEDIUM

Key Information:

Vendor
Apple
Vendor
CVE Published:
10 January 2024

Summary

A security issue has been identified in various Apple operating systems, involving an out-of-bounds read that may occur during image processing. If exploited, this vulnerability could allow unauthorized disclosure of process memory, potentially compromising sensitive data within applications. Apple has addressed this issue through improved input validation processes in the latest updates for macOS Ventura 13.3, tvOS 16.4, iOS 16.4, iPadOS 16.4, and watchOS 9.4.

Affected Version(s)

iOS and iPadOS < 16.4

macOS < 13.3

tvOS < 16.4

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.