CVE-2023-23494: Buffer Overflow
A buffer overflow was addressed with improved bounds checking. This issue is fixed in iOS 16.4 and iPadOS 16.4. A user in a privileged network position may be able to cause a denial-of-service
Other sources
Accessibility. A privacy issue was addressed with improved private data redaction for log entries.
— Apple
App Store. A privacy issue was addressed with improved private data redaction for log entries.
— Apple
Apple Neural Engine. An out-of-bounds write issue was addressed with improved bounds checking.
— Apple
Apple Neural Engine. The issue was addressed with improved memory handling.
— Apple
Apple Neural Engine. This issue was addressed with improved checks.
— Apple
Credit
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2023-23541
- CVE-2023-42830
- CVE-2023-23540
- CVE-2023-27959
- CVE-2023-27970
- CVE-2023-23532
- CVE-2023-23527
- CVE-2023-27931
- CVE-2023-27961
- CVE-2023-23543
- CVE-2023-23494
- CVE-2023-27955
- CVE-2023-23528
- CVE-2023-28181
- CVE-2023-40398
- CVE-2023-28195
- CVE-2023-23537
- CVE-2023-32366
- CVE-2023-27956
- CVE-2023-27937
- CVE-2023-23526
- CVE-2023-27928
- CVE-2023-23535
- CVE-2023-27929
- CVE-2023-42862
- CVE-2023-42865
- CVE-2023-28187
- CVE-2023-28185
- CVE-2023-32424
- CVE-2023-27969
- CVE-2023-27933
- CVE-2023-23536
- CVE-2023-27943
- CVE-2023-23525
- CVE-2023-41075
- CVE-2022-46724
- CVE-2023-28182
- CVE-2023-23523
- CVE-2023-27942
- CVE-2023-28194
- CVE-2023-28178
- CVE-2023-27963
- CVE-2023-28188
- CVE-2023-32370
- CVE-2023-28198
- CVE-2022-46725
- CVE-2023-32435
- CVE-2023-27932
- CVE-2023-27954
- CVE-2022-46705
- CVE-2014-1745
- CVE-2023-32358
- CVE-2023-28201
Frequently Asked Questions
What is the vulnerability ID of this issue?
The vulnerability ID is CVE-2023-23494.
What is the title of this vulnerability?
The title of this vulnerability is 'CarPlay. A buffer overflow was addressed with improved bounds checking.'
What is the severity rating of CVE-2023-23494?
The severity rating of CVE-2023-23494 is medium with a score of 5.3.
Which software versions are affected by this vulnerability?
This vulnerability affects iOS versions up to but not including 16.4, iPadOS versions up to but not including 16.4, Apple watchOS, and Apple iPhone OS.
How can I fix this vulnerability?
This vulnerability is fixed in iOS 16.4 and iPadOS 16.4. Ensure that you update your device to the latest available version.