CVE-2023-42939Improper Enforcement of Behavioral Workflow in Apple IOS AND Ipados

Severity
3.3LOWNVD
EPSS
0.0%
top 95.38%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 21

Description

A logic issue was addressed with improved checks. This issue is fixed in iOS 17.1 and iPadOS 17.1. A user's private browsing activity may be unexpectedly saved in the App Privacy Report.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:NExploitability: 1.8 | Impact: 1.4

Affected Packages3 packages

NVDapple/ipad_os< 17.1
CVEListV5apple/ios_and_ipadosunspecified17.1
NVDapple/iphone_os< 17.1

🔴Vulnerability Details

2
CVEList
CVE-2023-42939: A logic issue was addressed with improved checks2024-02-21
GHSA
GHSA-c537-pf3w-23p5: A logic issue was addressed with improved checks2024-02-21

📋Vendor Advisories

1
Apple
CVE-2023-42939: iOS 17.1 and iPadOS 17.12023-10-25
CVE-2023-42939 — Apple IOS AND Ipados vulnerability | cvebase