CVE-2023-32437: Input Validation
Accessibility. A privacy issue was addressed with improved private data redaction for log entries.
Other sources
Accessibility. This issue was addressed with improved checks.
— Apple
Accounts. A permissions issue was addressed with improved redaction of sensitive information.
— Apple
Accounts. A privacy issue was addressed with improved private data redaction for log entries.
— Apple
AMD. A buffer overflow issue was addressed with improved memory handling.
— Apple
Apple Neural Engine. The issue was addressed with improved memory handling.
— Apple
Credit
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2023-32400
- CVE-2023-34352
- CVE-2023-32411
- CVE-2023-32399
- CVE-2023-28191
- CVE-2023-32392
- CVE-2023-32372
- CVE-2023-32384
- CVE-2023-32354
- CVE-2023-32420
- CVE-2023-27930
- CVE-2023-32398
- CVE-2023-32413
- CVE-2023-32352
- CVE-2023-32428
- CVE-2023-32407
- CVE-2023-32368
- CVE-2023-32403
- CVE-2023-32437
- CVE-2023-32390
- CVE-2023-32357
- CVE-2023-32432
- CVE-2023-32391
- CVE-2023-32404
- CVE-2023-32394
- CVE-2023-32422
- CVE-2023-32376
- CVE-2023-28202
- CVE-2023-32412
- CVE-2023-32408
- CVE-2023-32415
- CVE-2023-32402
- CVE-2023-32423
- CVE-2023-32409
- CVE-2023-28204
- CVE-2023-32373
- CVE-2023-32389
- CVE-2023-32388
- CVE-2023-32425
- CVE-2023-32417
- CVE-2023-32379
- CVE-2023-32383
- CVE-2023-32371
- CVE-2023-32386
- CVE-2023-32360
- CVE-2023-32387
- CVE-2023-32414
- CVE-2023-32410
- CVE-2023-27940
- CVE-2023-29469
- CVE-2023-42869
- CVE-2023-32369
- CVE-2023-32405
- CVE-2023-42958
- CVE-2023-32375
- CVE-2023-32382
- CVE-2023-32380
- CVE-2023-32355
- CVE-2023-32385
- CVE-2023-32395
- CVE-2023-32401
- CVE-2023-32363
- CVE-2023-32367
- CVE-2023-32397
- CVE-2023-22809
- CVE-2023-32419
- CVE-2023-32365
- CVE-2023-40442
- CVE-2023-40439
- CVE-2023-34425
- CVE-2023-38136
- CVE-2023-38580
- CVE-2023-40392
- CVE-2023-40437
- CVE-2023-32416
- CVE-2022-3970
- CVE-2023-38590
- CVE-2023-38598
- CVE-2023-36495
- CVE-2023-38604
- CVE-2023-32734
- CVE-2023-32441
- CVE-2023-38261
- CVE-2023-38424
- CVE-2023-38425
- CVE-2023-38606
- CVE-2023-32381
- CVE-2023-32433
- CVE-2023-35993
- CVE-2023-41995
- CVE-2023-38410
- CVE-2023-38603
- CVE-2023-40400
- CVE-2023-38565
- CVE-2023-38593
- CVE-2023-40394
- CVE-2023-38605
- CVE-2023-40397
- CVE-2023-38599
- CVE-2023-32445
- CVE-2023-38592
- CVE-2023-38572
- CVE-2023-38594
- CVE-2023-38595
- CVE-2023-38600
- CVE-2023-38611
- CVE-2023-37450
- CVE-2023-42866
- CVE-2023-38597
- CVE-2023-38133
- CVE-2023-43000
Frequently Asked Questions
What is CVE-2023-32437?
CVE-2023-32437 is a vulnerability in NSURLSession that allows an app to break out of its sandbox in iOS 16.6 and iPadOS 16.6.
How does CVE-2023-32437 affect Apple products?
CVE-2023-32437 affects Apple products such as iOS, iPadOS, iPhone OS, tvOS, watchOS, and macOS Ventura.
What is the severity of CVE-2023-32437?
The severity of CVE-2023-32437 is high, with a severity value of 8.6.
How can I fix CVE-2023-32437?
To fix CVE-2023-32437, update your iOS or iPadOS device to version 16.6 or higher.
Where can I find more information about CVE-2023-32437?
You can find more information about CVE-2023-32437 on the Apple support website.