CVE-2023-32417Apple Watchos vulnerability

4 documents3 sources
Severity
2.4LOWNVD
EPSS
0.1%
top 77.36%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 23

Description

This issue was addressed by restricting options offered on a locked device. This issue is fixed in watchOS 9.5. An attacker with physical access to a locked Apple Watch may be able to view user photos or contacts via accessibility features.

CVSS vector

CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:NExploitability: 0.9 | Impact: 1.4

Affected Packages4 packages

CVEListV5apple/watchosunspecified9.5
NVDapple/watchos< 9.5
Appleapple/watchos9.5

🔴Vulnerability Details

1
GHSA
GHSA-pjqg-7hp6-p4f6: This issue was addressed by restricting options offered on a locked device2023-06-23

📋Vendor Advisories

2
Apple
CVE-2023-32417: macOS Ventura 13.42023-05-18
Apple
CVE-2023-32417: watchOS 9.52023-05-18