CVE-2023-32385: Buffer Overflow
A denial-of-service issue was addressed with improved memory handling. This issue is fixed in iOS 16.5 and iPadOS 16.5, macOS Ventura 13.4. Opening a PDF file may lead to unexpected app termination.
Other sources
Accessibility. A privacy issue was addressed with improved private data redaction for log entries.
— Apple
Accessibility. This issue was addressed with improved checks.
— Apple
Accounts. A permissions issue was addressed with improved redaction of sensitive information.
— Apple
AMD. A buffer overflow issue was addressed with improved memory handling.
— Apple
Apple Neural Engine. The issue was addressed with improved memory handling.
— Apple
Credit
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2023-32388
- CVE-2023-32400
- CVE-2023-34352
- CVE-2023-32379
- CVE-2023-32411
- CVE-2023-32383
- CVE-2023-32371
- CVE-2023-32386
- CVE-2023-32399
- CVE-2023-28191
- CVE-2023-32360
- CVE-2023-32387
- CVE-2023-32414
- CVE-2023-32417
- CVE-2023-32392
- CVE-2023-32372
- CVE-2023-32384
- CVE-2023-32410
- CVE-2023-32420
- CVE-2023-27930
- CVE-2023-27940
- CVE-2023-32398
- CVE-2023-32413
- CVE-2023-32352
- CVE-2023-29469
- CVE-2023-42869
- CVE-2023-32369
- CVE-2023-32405
- CVE-2023-32428
- CVE-2023-32407
- CVE-2023-42958
- CVE-2023-32368
- CVE-2023-32375
- CVE-2023-32382
- CVE-2023-32380
- CVE-2023-32403
- CVE-2023-32437
- CVE-2023-32355
- CVE-2023-32385
- CVE-2023-32395
- CVE-2023-32390
- CVE-2023-32401
- CVE-2023-32357
- CVE-2023-32363
- CVE-2023-32367
- CVE-2023-32432
- CVE-2023-32397
- CVE-2023-32391
- CVE-2023-32404
- CVE-2023-32394
- CVE-2023-32422
- CVE-2023-32376
- CVE-2023-22809
- CVE-2023-28202
- CVE-2023-32412
- CVE-2023-32408
- CVE-2023-32415
- CVE-2023-32402
- CVE-2023-32423
- CVE-2023-32409
- CVE-2023-28204
- CVE-2023-32373
- CVE-2023-32389
- CVE-2023-32425
- CVE-2023-32419
- CVE-2023-32354
- CVE-2023-32365
Frequently Asked Questions
What is CVE-2023-32385?
CVE-2023-32385 is a denial-of-service vulnerability in PDFKit that can cause unexpected app termination when opening a PDF file.
How does CVE-2023-32385 affect iOS and iPadOS?
CVE-2023-32385 affects iOS and iPadOS versions up to and including 16.5, causing unexpected app termination when opening a PDF file.
How does CVE-2023-32385 affect macOS Ventura?
CVE-2023-32385 affects macOS Ventura versions up to and including 13.4, causing unexpected app termination when opening a PDF file.
What is the severity of CVE-2023-32385?
CVE-2023-32385 has a severity of 5.5 (medium).
How is CVE-2023-32385 fixed?
CVE-2023-32385 is fixed in iOS 16.5, iPadOS 16.5, and macOS Ventura 13.4 with improved memory handling.