CVE-2023-32383: Buffer Overflow
Published May 18, 2023
·Updated
Accessibility. A privacy issue was addressed with improved private data redaction for log entries.
Credit
James Duffy (mangoSecure), Kirin@@Pwnrin, Mickey Jin@@patch1t, Sergii Kryvoblotskyi(MacPaw Inc), ABC Research s.r.o., Adam M., Gerhard Muth, Dimitrios Tatsis(Cisco Talos), Zitong Wu (吴梓桐)(Zhuhai No), Meysam Firouzi@@R00tkitSMM(Mbition Mercedes), Meysam Firouzi@@R00tkitsmm(Trend Micro Zero Day Initiative), hou xuewei vmk msu@@p1ay8y3ar, CertiK SkyFall Team(Pinauten GmbH), Linus Henze(Pinauten GmbH), 08Tc3wBB(Jamf), Adam Doupé(ASU SEFCOM), Eloi Benoist-Vanderbeken@@elvanderb(Synacktiv), Wojciech Reguła@@_r3ggi(SecuRing), OSS-Fuzz(Google Project Zero), Ned Williamson(Google Project Zero), Jonathan Bar Or(Microsoft), Anurag Bohra(Microsoft), (Microsoft), Michael Pearse(Microsoft), Thijs Alkemade@@xnyhps(Computest Sector 7), Gergely Kalman@@gergely_kalman, Michael DePlante@@izobashi(Trend Micro Zero Day Initiative), Thijs Alkemade(Computest Sector 7), Jonathan Fritz, Arsenii Kostromin (0x3c3e), Julian Szulc, Holger Fuhrmannek(Deutsche Telekom Security GmbH on behalf of BSI), Yiğit Can YILMAZ@@yilmazcanyigit(FFRI Security Inc), Koh M. Nakagawa(FFRI Security Inc), Kirin@@Pwnrin(Offensive Security), Jeff Johnson (underpassapp.com)(Offensive Security), (Offensive Security), Csaba Fitzl@@theevilbit(Offensive Security), Wenchao Li(Alibaba Group), Xiaolong Bai(Alibaba Group), Mickey Jin@@patch1t(Tencent Security Xuanwu Lab), Zhipeng Huo@@R3dF09(Tencent Security Xuanwu Lab), an anonymous researcher, Khiem Tran, Gergely Kalman@@gergely_kalman(SecuRing), (SecuRing), Wojciech Reguła(SecuRing), Yiğit Can YILMAZ@@yilmazcanyigit, CVE-2023-22809, Satish Panduranga, Ivan Fratric(Google Project Zero), Wojciech Regula(SecuRing), Ignacio Sanmillan@@ulexec, Clément Lecigne(Google's Threat Analysis Group), Donncha Ó Cearbhaill(Amnesty International), Pan ZhenPeng@@Peterpan0927(STAR Labs SG Pte)
Affected Software
6 affected componentsFixes available
Apple macOS Big Sur<11.7.7
11.7.7
macOS<12.6.6
12.6.6
macOS Ventura<13.4
13.4
macOS<11.7.7
macOS>=12.0.0<12.6.6
macOS>=13.0<13.4
Event History
Jan 10, 2024
CVE Published
via MITRE·10:03 PM
Data Sourced
via MITRE·10:03 PM
DescriptionWeakness
Data Sourced
via NVD·10:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2023-32383?
CVE-2023-32383 is rated as high severity due to its potential impact on user privacy and data security.
2
How do I fix CVE-2023-32383?
To fix CVE-2023-32383, users should update to the latest version of macOS which addresses the vulnerabilities.
3
What operating systems are affected by CVE-2023-32383?
CVE-2023-32383 affects macOS versions including Catalina, Big Sur, Monterey, and Ventura.
4
What type of vulnerabilities are addressed by CVE-2023-32383?
CVE-2023-32383 addresses privacy issues, permissions issues, and a buffer overflow vulnerability.
5
Are there any workarounds for CVE-2023-32383?
There are no specific workarounds for CVE-2023-32383 other than applying the recommended software updates.