CVE-2023-40435

4 documents4 sources
Severity
5.5MEDIUM
EPSS
0.1%
top 68.49%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedSep 27

Description

This issue was addressed by enabling hardened runtime. This issue is fixed in Xcode 15. An app may be able to access App Store credentials.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:NExploitability: 1.8 | Impact: 3.6

Affected Packages2 packages

โ–ถCVEListV5apple/xcodeunspecified โ€” 15
โ–ถNVDapple/xcode< 15.0

๐Ÿ”ดVulnerability Details

2
GHSA
GHSA-jfrq-hgvj-jh7r: This issue was addressed by enabling hardened runtimeโ†—2023-09-27
โ–ถ
CVEList
CVE-2023-40435: This issue was addressed by enabling hardened runtimeโ†—2023-09-26
โ–ถ

๐Ÿ“‹Vendor Advisories

1
Apple
CVE-2023-40435: Xcode 15โ†—2023-09-18
โ–ถ