CVE-2023-32437: Input Validation

Published May 18, 2023
·
Updated

Accessibility. A privacy issue was addressed with improved private data redaction for log entries.

Other sources

Accessibility. This issue was addressed with improved checks.

Apple

Accounts. A permissions issue was addressed with improved redaction of sensitive information.

Apple

Accounts. A privacy issue was addressed with improved private data redaction for log entries.

Apple

AMD. A buffer overflow issue was addressed with improved memory handling.

Apple

Apple Neural Engine. The issue was addressed with improved memory handling.

Apple

Credit

Mickey Jin@@patch1t, Sergii Kryvoblotskyi(MacPaw Inc), Adam M., Meysam Firouzi@@R00tkitSMM(Mbition Mercedes), Meysam Firouzi@@R00tkitsmm(Trend Micro Zero Day Initiative), Linus Henze(Pinauten GmbH), CertiK SkyFall Team(Pinauten GmbH), 08Tc3wBB(Jamf), Adam Doupé(ASU SEFCOM), Eloi Benoist-Vanderbeken@@elvanderb(Synacktiv), Wojciech Reguła@@_r3ggi(SecuRing), Gergely Kalman@@gergely_kalman, Thijs Alkemade(Computest Sector 7), Julian Szulc, Yiğit Can YILMAZ@@yilmazcanyigit(FFRI Security Inc), Koh M. Nakagawa(FFRI Security Inc), Kirin@@Pwnrin(Offensive Security), Jeff Johnson (underpassapp.com)(Offensive Security), (Offensive Security), Csaba Fitzl@@theevilbit(Offensive Security), Kirin@@Pwnrin, Wenchao Li(Alibaba Group), Xiaolong Bai(Alibaba Group), Zhipeng Huo@@R3dF09(Tencent Security Xuanwu Lab), an anonymous researcher, Khiem Tran, Gergely Kalman@@gergely_kalman(SecuRing), (SecuRing), Wojciech Reguła(SecuRing), Yiğit Can YILMAZ@@yilmazcanyigit, Satish Panduranga, Ivan Fratric(Google Project Zero), Wojciech Regula(SecuRing), Ignacio Sanmillan@@ulexec, Clément Lecigne(Google's Threat Analysis Group), Donncha Ó Cearbhaill(Amnesty International), Pan ZhenPeng@@Peterpan0927(STAR Labs SG Pte), Mickey Jin@@patch1t(Tencent Security Xuanwu Lab), Zitong Wu (吴梓桐)(Zhuhai No), Mohamed GHANNAM@@_simo36, Jonathan Fritz, Jiwon Park, James Duffy (mangoSecure), OSS-Fuzz(Google Project Zero), (Google Project Zero), Ned Williamson(Google Project Zero), Amat Cama(Vigilant Labs), Thijs Alkemade@@xnyhps(Computest Sector 7), Michael DePlante@@izobashi(Trend Micro Zero Day Initiative), Arsenii Kostromin (0x3c3e), Holger Fuhrmannek(Deutsche Telekom Security GmbH on behalf of BSI), CVE-2023-22809, Gerhard Muth, Dimitrios Tatsis(Cisco Talos), hou xuewei vmk msu@@p1ay8y3ar, Jonathan Bar Or(Microsoft), Anurag Bohra(Microsoft), (Microsoft), Michael Pearse(Microsoft), ABC Research s.r.o., Nick Brook, pattern-f@@pattern_F_(Ant Security Light), Kirin@@Pwnrin(SecuRing), found by OSS-Fuzz, Zweig(Kunlun Lab), 香农的三蹦子(Pangu Lab), Peter Nguyễn Vũ Hoàng@@peternguyen14(STAR Labs SG Pte), Certik Skyfall Team, Valentin Pashkov(Kaspersky), Mikhail Vinogradov(Kaspersky), Georgy Kucherin@@kucher1n(Kaspersky), Leonid Bezvershenko@@bzvr_(Kaspersky), (Kaspersky), Boris Larin@@oct0xor(Kaspersky), Kaitao Xie(Alibaba Group), Certik Skyfall Team(Ant Security Light), Sei K., Noah Roskin-Frazee, Johan Carlsson (joaxcar), Hritvik Taneja, Jason Kim, Jie Jeff Xu, Stephan van Schaik, Daniel Genkin, Yuval Yarom, Narendra Bhati (twitter.com/imnarendrabhati)(Suma Soft Pvt), Pune - India(TU Wien), Valentino Dalla Valle(TU Wien), Pedro Bernardo(TU Wien), Marco Squarcina(TU Wien), (TU Wien), Lorenzo Veronese(TU Wien), Pune - India, Yuhao Hu, Jiming Wang, Jikai Ren, Anonymous(Trend Micro Zero Day Initiative), Francisco Alonso@@revskills, Junsung Lee, 이준성(Junsung Lee)(Cross Republic), Apple, YeongHyeon Choi@@hyeon101010

Affected Software

7 affected componentsFixes available
Apple tvOS<16.5
16.5
Apple WatchOS<9.5
9.5
Apple macOS Ventura<13.4
13.4
Apple iOS<16.5
16.5
Apple iPadOS<16.5
16.5
Apple iPadOS<16.6
Apple iPhone OS<16.6

Event History

Jul 24, 2023
Data Sourced
via Apple·12:00 AM
DescriptionWeaknessAffected Software
Updated
via Apple·12:00 AM
DescriptionWeakness
Jul 26, 2023
CVE Published
via MITRE·11:55 PM
Data Sourced
via MITRE·11:55 PM
DescriptionWeakness

Peer vulnerabilities

Found alongside the following vulnerabilities.

Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is CVE-2023-32437?

CVE-2023-32437 is a vulnerability in NSURLSession that allows an app to break out of its sandbox in iOS 16.6 and iPadOS 16.6.

2

How does CVE-2023-32437 affect Apple products?

CVE-2023-32437 affects Apple products such as iOS, iPadOS, iPhone OS, tvOS, watchOS, and macOS Ventura.

3

What is the severity of CVE-2023-32437?

The severity of CVE-2023-32437 is high, with a severity value of 8.6.

4

How can I fix CVE-2023-32437?

To fix CVE-2023-32437, update your iOS or iPadOS device to version 16.6 or higher.

5

Where can I find more information about CVE-2023-32437?

You can find more information about CVE-2023-32437 on the Apple support website.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203