CVE-2023-42853Improper Access Control in Apple Macos

Severity
5.5MEDIUMNVD
EPSS
0.0%
top 93.79%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 21
Latest updateMar 7

Description

A logic issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14.1, macOS Monterey 12.7.1, macOS Ventura 13.6.1. An app may be able to access user-sensitive data.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:NExploitability: 1.8 | Impact: 3.6

Affected Packages5 packages

Appleapple/macos_sonoma14.1, 14.4+1
Appleapple/macos_ventura13.6.1
Appleapple/macos_monterey12.7.1
CVEListV5apple/macosunspecified14.1+2
NVDapple/macos13.013.6.1+2

🔴Vulnerability Details

1
GHSA
GHSA-pp42-3grw-xrgx: A logic issue was addressed with improved checks2024-02-21

📋Vendor Advisories

4
Apple
CVE-2023-42853: macOS Sonoma 14.42024-03-07
Apple
CVE-2023-42853: macOS Sonoma 14.12023-10-25
Apple
CVE-2023-42853: macOS Ventura 13.6.12023-10-25
Apple
CVE-2023-42853: macOS Monterey 12.7.12023-10-25