Memory Handling Vulnerability in Apple Products
CVE-2023-42898

5.5MEDIUM

Key Information:

Vendor
Apple
Vendor
CVE Published:
12 December 2023

Summary

A memory handling issue in Apple's software can lead to arbitrary code execution when processing crafted images. This vulnerability affects various Apple platforms, necessitating updates to macOS Sonoma 14.2, watchOS 10.2, iOS 17.2, iPadOS 17.2, and tvOS 17.2 to mitigate potential exploitation. Users are urged to apply available patches immediately to secure their devices.

Affected Version(s)

iOS and iPadOS < 17.2

macOS < 14.2

tvOS < 17.2

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.