CVE-2023-23502 — Out-of-bounds Read in Apple IOS AND Ipados
Severity
5.5MEDIUMNVD
EPSS
0.1%
top 64.85%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedFeb 27
Description
An information disclosure issue was addressed by removing the vulnerable code. This issue is fixed in macOS Monterey 12.6.3, macOS Ventura 13.2, iOS 16.3 and iPadOS 16.3, tvOS 16.3, watchOS 9.3. An app may be able to determine kernel memory layout.
CVSS vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:NExploitability: 1.8 | Impact: 3.6
Affected Packages14 packages
🔴Vulnerability Details
1GHSA▶
GHSA-4948-rc3p-cvv8: An information disclosure issue was addressed by removing the vulnerable code↗2023-02-27