Denial-of-Service and Memory Disclosure Vulnerability in Apple macOS Products
CVE-2023-42876

7.1HIGH

Key Information:

Vendor
Apple
Status
Vendor
CVE Published:
10 January 2024

Summary

A vulnerability in Apple's macOS products allows for potential denial-of-service scenarios or unauthorized memory content disclosure. This issue arises from inadequate bounds checks when processing specific files. Users of macOS Sonoma 14 should ensure they have the latest updates to mitigate this risk, as the vulnerability has been addressed with improvements in the bounds checking mechanism.

Affected Version(s)

macOS < 14

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.