Memory Handling Flaw in Apple Operating Systems
CVE-2023-42914

6.3MEDIUM

Key Information:

Vendor
Apple
Vendor
CVE Published:
12 December 2023

Summary

A vulnerability has been identified in Apple’s operating systems that could allow applications to break out of their designated sandbox. This issue stems from improper memory handling, potentially leading to unauthorized access to system resources. It impacts various versions of macOS, iOS, iPadOS, watchOS, and tvOS, prompting users to update their devices to the latest software versions to mitigate associated risks.

Affected Version(s)

iOS and iPadOS < 17.2

iOS and iPadOS < 16.7

macOS < 13.6

References

CVSS V3.1

Score:
6.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.