CVE-2023-32425
Published May 18, 2023
·Updated
Accessibility. A privacy issue was addressed with improved private data redaction for log entries.
Credit
Mohamed Ghannam@@_simo36, Mohamed GHANNAM@@_simo36, Sergii Kryvoblotskyi(MacPaw Inc), Mickey Jin@@patch1t, James Duffy (mangoSecure), Amat Cama(Vigilant Labs), Adam M., Meysam Firouzi@@R00tkitSMM(Mbition Mercedes), Meysam Firouzi@@R00tkitsmm(Trend Micro Zero Day Initiative), Linus Henze(Pinauten GmbH), CertiK SkyFall Team(Pinauten GmbH), 08Tc3wBB(Jamf), Adam Doupé(ASU SEFCOM), Eloi Benoist-Vanderbeken@@elvanderb(Synacktiv), Wojciech Reguła@@_r3ggi(SecuRing), OSS-Fuzz(Google Project Zero), (Google Project Zero), Ned Williamson(Google Project Zero), Gergely Kalman@@gergely_kalman, Thijs Alkemade(Computest Sector 7), Jonathan Fritz, Jiwon Park, Julian Szulc, Yiğit Can YILMAZ@@yilmazcanyigit(FFRI Security Inc), Koh M. Nakagawa(FFRI Security Inc), Kirin@@Pwnrin(Offensive Security), Jeff Johnson (underpassapp.com)(Offensive Security), (Offensive Security), Csaba Fitzl@@theevilbit(Offensive Security), Kirin@@Pwnrin, Wenchao Li(Alibaba Group), Xiaolong Bai(Alibaba Group), Mickey Jin@@patch1t(Tencent Security Xuanwu Lab), Zhipeng Huo@@R3dF09(Tencent Security Xuanwu Lab), an anonymous researcher, Khiem Tran, Gergely Kalman@@gergely_kalman(SecuRing), (SecuRing), Wojciech Reguła(SecuRing), Yiğit Can YILMAZ@@yilmazcanyigit, Satish Panduranga, Ivan Fratric(Google Project Zero), Wojciech Regula(SecuRing), Ignacio Sanmillan@@ulexec, Clément Lecigne(Google's Threat Analysis Group), Donncha Ó Cearbhaill(Amnesty International), Pan ZhenPeng@@Peterpan0927(STAR Labs SG Pte), Zitong Wu (吴梓桐)(Zhuhai No)
Affected Software
9 affected componentsFixes available
Apple WatchOS<9.5
9.5
Apple Ipad Os<16.5
Apple iPhone OS<16.5
Apple WatchOS<9.5
Apple iOS<16.5
16.5
Apple iPadOS<16.5
16.5
Apple iOS<15.7.6
15.7.6
Apple iPadOS<15.7.6
15.7.6
Apple iPadOS<16.5
Event History
May 18, 2023
Data Sourced
via Apple·12:00 AM
DescriptionWeaknessAffected Software
Updated
via Apple·12:00 AM
DescriptionWeakness
Updated
via Apple·12:00 AM
Affected Software
Updated
via Apple·12:00 AM
DescriptionWeaknessAffected Software
Sep 6, 2023
CVE Published
via MITRE·01:36 AM
Data Sourced
via MITRE·01:36 AM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2023-32425?
The severity of CVE-2023-32425 is high (7.8).
2
How was CVE-2023-32425 fixed?
CVE-2023-32425 was fixed with improved memory handling in iOS 16.5 and iPadOS 16.5, watchOS 9.5.
3
Which Apple products are affected by CVE-2023-32425?
The affected products include Apple watchOS (up to version 9.5), Apple iOS (up to version 16.5), and Apple iPadOS (up to version 16.5).
4
Can an app gain elevated privileges through CVE-2023-32425?
Yes, an app may be able to gain elevated privileges through CVE-2023-32425.
5
Where can I find more information about CVE-2023-32425?
You can find more information about CVE-2023-32425 on the Apple support website.