CVE-2023-42977
published 2025-04-11CVE-2023-42977: A path handling issue was addressed with improved validation. This issue is fixed in iOS 17 and iPadOS 17, macOS Sonoma 14. An app may be able to break out of…
PriorityP335high7.8CVSS 3.1
AVLACLPRNUIRSUCHIHAH
EPSS
0.20%
10.3th percentile
A path handling issue was addressed with improved validation. This issue is fixed in iOS 17 and iPadOS 17, macOS Sonoma 14. An app may be able to break out of its sandbox.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | ios_17_and_ipados | — | — |
| apple | ios_and_ipados | >= unspecified < 17 | 17 |
| apple | ipad_os | < 17.0 | 17.0 |
| apple | iphone_os | < 17.0 | 17.0 |
| apple | macos | < 14.0 | 14.0 |
| apple | macos | >= unspecified < 14 | 14 |
| apple | macos_sonoma | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-m6p7-g6ff-wxw5: A path handling issue was addressed with improved validation
ghsa_unreviewed·2025-04-11
CVE-2023-42977 [HIGH] CWE-20 GHSA-m6p7-g6ff-wxw5: A path handling issue was addressed with improved validation
A path handling issue was addressed with improved validation. This issue is fixed in iOS 17 and iPadOS 17, macOS Sonoma 14. An app may be able to break out of its sandbox.
Apple
CVE-2023-42977: macOS Sonoma 14
vendor_apple·2023-09-26·CVSS 7.8
CVE-2023-42977 [HIGH] CVE-2023-42977: macOS Sonoma 14
Apple Security Update: About the security content of macOS Sonoma 14
Product: macOS Sonoma
Version: 14
CVE: CVE-2023-42977
Component: Power Services
Impact: An app may be able to break out of its sandbox
Description: A path handling issue was addressed with improved validation.
Apple
CVE-2023-42977: iOS 17 and iPadOS 17
vendor_apple·2023-09-18·CVSS 7.8
CVE-2023-42977 [HIGH] CVE-2023-42977: iOS 17 and iPadOS 17
Apple Security Update: About the security content of iOS 17 and iPadOS 17
Product: iOS 17 and iPadOS
Version: 17
CVE: CVE-2023-42977
Component: Power Services
Impact: An app may be able to break out of its sandbox
Description: A path handling issue was addressed with improved validation.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2025-04-11
Published