CVE-2023-36862Apple Macos vulnerability

3 documents3 sources
Severity
5.5MEDIUMNVD
EPSS
0.1%
top 80.17%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 27

Description

A downgrade issue affecting Intel-based Mac computers was addressed with additional code-signing restrictions. This issue is fixed in macOS Ventura 13.5. An app may be able to determine a user’s current location.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:NExploitability: 1.8 | Impact: 3.6

Affected Packages3 packages

CVEListV5apple/macosunspecified13.5
NVDapple/macos13.013.5

🔴Vulnerability Details

1
GHSA
GHSA-fxwr-68rr-mp8h: A downgrade issue affecting Intel-based Mac computers was addressed with additional code-signing restrictions2023-07-27

📋Vendor Advisories

1
Apple
CVE-2023-36862: macOS Ventura 13.52023-07-24