CVE-2023-28207: Use After Free
Published Mar 27, 2023
·Updated
AMD. A buffer overflow issue was addressed with improved memory handling.
Credit
Wojciech Reguła@@_r3ggi(SecuRing), Mickey Jin@@patch1t, Brandon Dalton@@partyD0lphin(Red Canary), Csaba Fitzl@@theevilbit(Offensive Security), Rıza Sabuncu@@rizasabuncu, JeongOhKyea, Tingting Yin(Tsinghua University), Aleksandar Nikolic(Cisco Talos), Adam M., Ye Zhang@@VAR10CK(Baidu Security), an anonymous researcher, Murray Mike, Arsenii Kostromin (0x3c3e), Félix Poulin-Bélanger, David Pan Ogea, Xinru Chi(Pangu Lab), Ned Williamson(Google Project Zero), sqrtpwn, Pan ZhenPeng(STAR Labs SG Pte), Zweig(Kunlun Lab), Joshua Jones, Zhuowei Zhang, Mickey Jin@@patch1t(FFRI Security Inc), Koh M. Nakagawa(FFRI Security Inc), (Offensive Security), Yiğit Can YILMAZ@@yilmazcanyigit, Jubaer Alnazi Jabin(TRS Group Of Companies), Wenchao Li(Alibaba Group), Xiaolong Bai(Alibaba Group), Guilherme Rambo(Best Buddy Apps), CVE-2023-0433, CVE-2023-0512, ryuzaki, Mohamed GHANNAM@@_simo36, Antonio Zekic@@antoniozekic, John Aakerblom@@jaakerblom, ABC Research s.r.o., Mohamed Ghannam@@_simo36, Chan Shue Long(Offensive Security), Junoh Lee at Theori, CVE-2022-43551, CVE-2022-43552, Mikko Kenttälä )@@Turmio_(SensorFu), Jubaer Alnazi(TRS Group of Companies), jzhu(Trend Micro Zero Day Initiative), Meysam Firouzi@@R00tkitSMM(Mbition Mercedes), Pan ZhenPeng@@Peterpan0927(STAR Labs SG Pte), Adam Doupé(ASU SEFCOM), an anonymous researcher(Red Canary), Milan Tenk(F), (F), Arthur Valiev(F), developStorm, Khiem Tran, Masahiro Kawada@@kawakatz(GMO Cybersecurity by Ierae), (Alibaba Group), Xin Huang@@11iaxH, CVE-2023-0049, CVE-2023-0051, CVE-2023-0054, CVE-2023-0288, Gertjan Franken(imec), KU Leuven, hazbinhotel(Trend Micro Zero Day Initiative), Georgy Kucherin@@kucher1n(Kaspersky), Leonid Bezvershenko@@bzvr_(Kaspersky), Boris Larin@@oct0xor(Kaspersky), (Kaspersky), Valentin Pashkov(Kaspersky), Anonymous(Trend Micro Zero Day Initiative), Dohyun Lee@@l33d0hyun(SSD Labs), crixer@@pwning_me(SSD Labs)
Affected Software
9 affected componentsFixes available
macOS<12.6.4
12.6.4
Apple macOS Big Sur<11.7.5
11.7.5
macOS Ventura<13.3
13.3
macOS<11.7.5
macOS>=12.0<12.6.4
macOS>=13.0<13.3
macOS Ventura<13.3
macOS<12.6.4
Apple macOS Big Sur<11.7.5
Event History
Mar 21, 2025
CVE Published
via MITRE·12:19 AM
Data Sourced
via MITRE·12:19 AM
DescriptionWeakness
Data Sourced
via NVD·01:15 AM
DescriptionSeverity
Frequently Asked Questions
1
What is the severity of CVE-2023-28207?
CVE-2023-28207 is considered a moderate severity vulnerability.
2
How do I fix CVE-2023-28207?
To mitigate CVE-2023-28207, upgrade to macOS Ventura 13.3, macOS Monterey 12.6.4, or macOS Big Sur 11.7.5.
3
What type of vulnerability is CVE-2023-28207?
CVE-2023-28207 is a vulnerability that involves insufficient permission checks in macOS.
4
Which versions of macOS are affected by CVE-2023-28207?
CVE-2023-28207 affects macOS Ventura prior to 13.3, macOS Monterey prior to 12.6.4, and macOS Big Sur prior to 11.7.5.
5
What can an attacker do with CVE-2023-28207?
An attacker exploiting CVE-2023-28207 may inherit app permissions and access user data.