CVE-2023-27970
Published Mar 27, 2023
·Updated
Accessibility. A privacy issue was addressed with improved private data redaction for log entries.
Credit
Mohamed GHANNAM@@_simo36, Mohamed GHANNAM, Mohamed Ghannam@@_simo36, Mickey Jin@@patch1t, Rıza Sabuncu@@rizasabuncu, Yiğit Can YILMAZ@@yilmazcanyigit, Itay Iellin(General Motors Product Cyber Security), Etienne Charron(Renault), Khadim Dieng(Renault), JeongOhKyea, Jianjun Dai(360 Vulnerability Research Institute), Guang Gong(360 Vulnerability Research Institute), Tingting Yin(Tsinghua University), Adam M., Ye Zhang@@VAR10CK(Baidu Security), an anonymous researcher, Jubaer Alnazi(TRS Group of Companies), Csaba Fitzl@@theevilbit(Offensive Security), ryuzaki, Meysam Firouzi@@R00tkitSMM(Mbition Mercedes), jzhu(Trend Micro Zero Day Initiative), Pan ZhenPeng@@Peterpan0927(STAR Labs SG Pte), Pan ZhenPeng(STAR Labs SG Pte), Zechao Cai@@Zech4o(Zhejiang University), Adam Doupé(ASU SEFCOM), sqrtpwn, Félix Poulin-Bélanger, David Pan Ogea, an anonymous researcher(Red Canary), Brandon Dalton@@partyD0lphin(Red Canary), Milan Tenk(F), (F), Arthur Valiev(F), Zweig(Kunlun Lab), Abhay Kailasia@@abhay_kailasia(Lakshmi Narain College Of Technology Bhopal), Zhuowei Zhang, developStorm, Anton Spivak, Jubaer Alnazi Jabin(TRS Group Of Companies), (Alibaba Group), Wenchao Li(Alibaba Group), Xiaolong Bai(Alibaba Group), Xin Huang@@11iaxH, Gertjan Franken(imec), KU Leuven, hazbinhotel(Trend Micro Zero Day Initiative), Hyeon Park@@tree_segment(Team ApplePIE), Georgy Kucherin@@kucher1n(Kaspersky), Leonid Bezvershenko@@bzvr_(Kaspersky), Boris Larin@@oct0xor(Kaspersky), (Kaspersky), Valentin Pashkov(Kaspersky), Anonymous(Trend Micro Zero Day Initiative), Dohyun Lee@@l33d0hyun(SSD Labs), crixer@@pwning_me(SSD Labs)
Affected Software
5 affected componentsFixes available
Apple Ipad Os<16.4
iPhone OS<16.4
Apple iOS and iPadOS<16.4
16.4
Apple iOS, iPadOS, and macOS<16.4
16.4
Apple iOS, iPadOS, and macOS<16.4
Event History
Mar 27, 2023
Data Sourced
via Apple·12:00 AM
DescriptionWeaknessAffected Software
Updated
via Apple·12:00 AM
DescriptionWeakness
May 8, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionWeakness
Data Sourced
08:15 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2023-27970?
The severity of CVE-2023-27970 is high with a score of 7.8.
2
How was the out-of-bounds write issue in CVE-2023-27970 addressed?
The out-of-bounds write issue in CVE-2023-27970 was addressed with improved bounds checking.
3
Which versions of iOS and iPadOS are affected by CVE-2023-27970?
iOS 16.4 and iPadOS 16.4 are affected by CVE-2023-27970.
4
How can an app exploit CVE-2023-27970?
An app may be able to execute arbitrary code with kernel privileges by exploiting CVE-2023-27970.
5
How can I fix CVE-2023-27970?
CVE-2023-27970 is fixed in iOS 16.4 and iPadOS 16.4, so make sure you update to those versions.