CVE-2023-40438
published 2024-01-10CVE-2023-40438: An issue was addressed with improved handling of temporary files. This issue is fixed in macOS Sonoma 14, iOS 16.7 and iPadOS 16.7. An app may be able to…
PriorityP422medium5.5CVSS 3.1
AVLACLPRNUIRSUCHINAN
EPSS
0.20%
9.9th percentile
An issue was addressed with improved handling of temporary files. This issue is fixed in macOS Sonoma 14, iOS 16.7 and iPadOS 16.7. An app may be able to access edited photos saved to a temporary directory.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | ios_16.7_and_ipados | — | — |
| apple | ios_and_ipados | >= unspecified < 16.7 | 16.7 |
| apple | ipados | < 16.7 | 16.7 |
| apple | iphone_os | < 16.7 | 16.7 |
| apple | macos | < 14.0 | 14.0 |
| apple | macos | >= unspecified < 14 | 14 |
| apple | macos_sonoma | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Apple
CVE-2023-40438: macOS Sonoma 14
vendor_apple·2023-09-26·CVSS 5.5
CVE-2023-40438 [MEDIUM] CVE-2023-40438: macOS Sonoma 14
Apple Security Update: About the security content of macOS Sonoma 14
Product: macOS Sonoma
Version: 14
CVE: CVE-2023-40438
Component: Core Image
Impact: An app may be able to access edited photos saved to a temporary directory
Description: An issue was addressed with improved handling of temporary files.
Apple
CVE-2023-40438: iOS 16.7 and iPadOS 16.7
vendor_apple·2023-09-21·CVSS 5.5
CVE-2023-40438 [MEDIUM] CVE-2023-40438: iOS 16.7 and iPadOS 16.7
Apple Security Update: About the security content of iOS 16.7 and iPadOS 16.7
Product: iOS 16.7 and iPadOS
Version: 16.7
CVE: CVE-2023-40438
Component: Core Image
Impact: An app may be able to access edited photos saved to a temporary directory
Description: An issue was addressed with improved handling of temporary files.
GHSA
GHSA-95h7-88rj-5gc6: An issue was addressed with improved handling of temporary files
ghsa_unreviewed·2024-01-11
CVE-2023-40438 [MEDIUM] CWE-379 GHSA-95h7-88rj-5gc6: An issue was addressed with improved handling of temporary files
An issue was addressed with improved handling of temporary files. This issue is fixed in macOS Sonoma 14, iOS 16.7 and iPadOS 16.7. An app may be able to access edited photos saved to a temporary directory.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2024-01-10
Published