CVE-2023-23528: Buffer Overflow
Accessibility. A privacy issue was addressed with improved private data redaction for log entries.
Other sources
An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in tvOS 16.4, iOS 16.4 and iPadOS 16.4. Processing a maliciously crafted Bluetooth packet may result in disclosure of process memory
App Store. A privacy issue was addressed with improved private data redaction for log entries.
— Apple
Apple Neural Engine. An out-of-bounds write issue was addressed with improved bounds checking.
— Apple
Apple Neural Engine. The issue was addressed with improved memory handling.
— Apple
Apple Neural Engine. This issue was addressed with improved checks.
— Apple
Credit
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2023-23527
- CVE-2023-27955
- CVE-2023-23528
- CVE-2023-28181
- CVE-2023-27956
- CVE-2023-27937
- CVE-2023-27928
- CVE-2023-23535
- CVE-2023-27929
- CVE-2023-42862
- CVE-2023-42865
- CVE-2023-23536
- CVE-2023-27969
- CVE-2023-27933
- CVE-2023-28185
- CVE-2023-27942
- CVE-2023-28178
- CVE-2023-27963
- CVE-2023-27931
- CVE-2023-27932
- CVE-2023-27954
- CVE-2023-28201
- CVE-2023-23541
- CVE-2023-42830
- CVE-2023-23540
- CVE-2023-27959
- CVE-2023-27970
- CVE-2023-23532
- CVE-2023-27961
- CVE-2023-23543
- CVE-2023-23494
- CVE-2023-40398
- CVE-2023-28195
- CVE-2023-23537
- CVE-2023-32366
- CVE-2023-23526
- CVE-2023-28187
- CVE-2023-32424
- CVE-2023-27943
- CVE-2023-23525
- CVE-2023-41075
- CVE-2022-46724
- CVE-2023-28182
- CVE-2023-23523
- CVE-2023-28194
- CVE-2023-28188
- CVE-2023-32370
- CVE-2023-28198
- CVE-2022-46725
- CVE-2023-32435
- CVE-2022-46705
- CVE-2014-1745
- CVE-2023-32358
Frequently Asked Questions
What is CVE-2023-23528?
CVE-2023-23528 is a vulnerability in Core Bluetooth that allows for an out-of-bounds read when processing a maliciously crafted Bluetooth packet, potentially resulting in the disclosure of process memory.
How does CVE-2023-23528 affect Apple devices?
CVE-2023-23528 affects Apple devices running tvOS, iOS, and iPadOS versions up to and including 16.4.
What is the severity of CVE-2023-23528?
CVE-2023-23528 has a severity rating of 6.5, which is considered medium.
How can I fix CVE-2023-23528?
CVE-2023-23528 is fixed in tvOS 16.4, iOS 16.4, and iPadOS 16.4. Update your Apple device to the latest available version to mitigate the vulnerability.
Where can I find more information about CVE-2023-23528?
You can find more information about CVE-2023-23528 on the Apple Support website: [https://support.apple.com/en-us/HT213674](https://support.apple.com/en-us/HT213674) and [https://support.apple.com/en-us/HT213676](https://support.apple.com/en-us/HT213676)