Memory Corruption Vulnerabilities in Apple libxml2
CVE-2023-42869

7.5HIGH

Key Information:

Vendor
Apple
Vendor
CVE Published:
10 January 2024

Summary

Recent findings highlight multiple memory corruption issues within Apple's libxml2, a core library used for parsing XML data. These vulnerabilities stemmed from inadequate input validation, which could potentially allow attackers to execute arbitrary code. Users running macOS Ventura 13.4, iOS 16.5, and iPadOS 16.5 are particularly affected. Apple has released updates that address these weaknesses, significantly enhancing the security posture of its operating systems by enforcing stricter input validation protocols. It is crucial for users to update their systems to mitigate risks associated with these vulnerabilities.

Affected Version(s)

iOS and iPadOS < 16.5

macOS < 13.4

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.