CVE-2023-32363: Buffer Overflow
A permissions issue was addressed by removing vulnerable code and adding additional checks. This issue is fixed in macOS Ventura 13.4. An app may be able to bypass Privacy preferences.
Other sources
Accessibility. A privacy issue was addressed with improved private data redaction for log entries.
— Apple
Accessibility. This issue was addressed with improved checks.
— Apple
Accounts. A permissions issue was addressed with improved redaction of sensitive information.
— Apple
AMD. A buffer overflow issue was addressed with improved memory handling.
— Apple
AppleMobileFileIntegrity. This issue was addressed by forcing hardened runtime on the affected binaries at the system level.
— Apple
Credit
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2023-32388
- CVE-2023-32400
- CVE-2023-34352
- CVE-2023-32379
- CVE-2023-32411
- CVE-2023-32383
- CVE-2023-32371
- CVE-2023-32386
- CVE-2023-32399
- CVE-2023-28191
- CVE-2023-32360
- CVE-2023-32387
- CVE-2023-32414
- CVE-2023-32417
- CVE-2023-32392
- CVE-2023-32372
- CVE-2023-32384
- CVE-2023-32410
- CVE-2023-32420
- CVE-2023-27930
- CVE-2023-27940
- CVE-2023-32398
- CVE-2023-32413
- CVE-2023-32352
- CVE-2023-29469
- CVE-2023-42869
- CVE-2023-32369
- CVE-2023-32405
- CVE-2023-32428
- CVE-2023-32407
- CVE-2023-42958
- CVE-2023-32368
- CVE-2023-32375
- CVE-2023-32382
- CVE-2023-32380
- CVE-2023-32403
- CVE-2023-32437
- CVE-2023-32355
- CVE-2023-32385
- CVE-2023-32395
- CVE-2023-32390
- CVE-2023-32401
- CVE-2023-32357
- CVE-2023-32363
- CVE-2023-32367
- CVE-2023-32432
- CVE-2023-32397
- CVE-2023-32391
- CVE-2023-32404
- CVE-2023-32394
- CVE-2023-32422
- CVE-2023-32376
- CVE-2023-22809
- CVE-2023-28202
- CVE-2023-32412
- CVE-2023-32408
- CVE-2023-32415
- CVE-2023-32402
- CVE-2023-32423
- CVE-2023-32409
- CVE-2023-28204
- CVE-2023-32373
- CVE-2023-32389
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2023-32363.
What is the description of the vulnerability?
The vulnerability is a permissions issue in the Screen Saver feature of macOS Ventura 13.4 and earlier, allowing an app to bypass Privacy preferences.
What is the severity of CVE-2023-32363?
The severity of CVE-2023-32363 is medium with a severity value of 5.5.
How was the vulnerability addressed?
The vulnerability was addressed by removing vulnerable code and adding additional checks in macOS Ventura 13.4.
How can I fix the vulnerability in macOS Ventura 13.4?
To fix the vulnerability, update your macOS Ventura to version 13.4 or later.