CVE-2023-36862: Race Condition
Published Jul 24, 2023
·Updated
A downgrade issue affecting Intel-based Mac computers was addressed with additional code-signing restrictions. This issue is fixed in macOS Ventura 13.5. An app may be able to determine a user’s current location.
Credit
Mickey Jin@@patch1t, pattern-f@@pattern_F_(Ant Security Light), Mohamed GHANNAM@@_simo36, Gergely Kalman@@gergely_kalman, Wojciech Regula(SecuRing), Erhad Husovic, Sei K., CVE-2023-28319, CVE-2023-28320, CVE-2023-28321, CVE-2023-28322, Kirin@@Pwnrin(SecuRing), (SecuRing), Bool(YunShangHuaAn), found by OSS-Fuzz, Arsenii Kostromin (0x3c3e), Zweig(Kunlun Lab), 香农的三蹦子(Pangu Lab), an anonymous researcher, Pan ZhenPeng@@Peterpan0927(STAR Labs SG Pte), Peter Nguyễn Vũ Hoàng@@peternguyen14(STAR Labs SG Pte), Certik Skyfall Team, Kaitao Xie(Alibaba Group), Xiaolong Bai(Alibaba Group), Valentin Pashkov(Kaspersky), Mikhail Vinogradov(Kaspersky), Georgy Kucherin@@kucher1n(Kaspersky), Leonid Bezvershenko@@bzvr_(Kaspersky), (Kaspersky), Boris Larin@@oct0xor(Kaspersky), Zhipeng Huo@@R3dF09(Tencent Security Xuanwu Lab), Noah Roskin-Frazee, Taavi Eomäe(Zone Media O), Mickey Jin@@patch1t(Trend Micro Zero Day Initiative), (Trend Micro Zero Day Initiative), Michael DePlante@@izobashi(Trend Micro Zero Day Initiative), CVE-2023-1916, Jonathan Bar Or(Microsoft), Emanuele Cozzi(Microsoft), (Microsoft), Michael Pearse(Microsoft), Csaba Fitzl@@theevilbit(Offensive Security), Sandipan Roy, James Duffy (mangoSecure), Michael Cowell, David Hoyt(Hoyt LLC), Wenchao Li(Hangzhou Orange Shield Information Technology Co), Xiaolong Bai(Hangzhou Orange Shield Information Technology Co), Ltd., CVE-2023-1801, Matthew Loewen, CVE-2023-2426, CVE-2023-2609, CVE-2023-2610, Yiğit Can YILMAZ@@yilmazcanyigit, Pr, Kirin@@Pwnrin, Yishu Wang, Adam M., Johan Carlsson (joaxcar), Narendra Bhati (twitter.com/imnarendrabhati)(Suma Soft Pvt), Pune - India, Hritvik Taneja, Jason Kim, Jie Jeff Xu, Stephan van Schaik, Daniel Genkin, Yuval Yarom, Pune - India(TU Wien), Valentino Dalla Valle(TU Wien), Pedro Bernardo(TU Wien), Marco Squarcina(TU Wien), (TU Wien), Lorenzo Veronese(TU Wien), Yuhao Hu, Jiming Wang, Jikai Ren, Anonymous(Trend Micro Zero Day Initiative), Francisco Alonso@@revskills, Junsung Lee, Apple, 이준성(Junsung Lee)(Cross Republic), YeongHyeon Choi@@hyeon101010, ABC Research s.r.o.
Affected Software
2 affected componentsFixes available
macOS Ventura<13.5
13.5
macOS>=13.0<13.5
Event History
Jul 24, 2023
Data Sourced
via Apple·12:00 AM
DescriptionWeaknessAffected Software
Updated
via Apple·12:00 AM
DescriptionWeakness
Jul 26, 2023
CVE Published
via MITRE·11:55 PM
Data Sourced
via MITRE·11:55 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2023-36862.
2
What is the title of the vulnerability?
The title of the vulnerability is 'AppleMobileFileIntegrity. A downgrade issue affecting Intel-based Mac computers was addressed with additional code-signing restrictions.'
3
What is the severity of CVE-2023-36862?
The severity of CVE-2023-36862 is medium with a severity value of 5.5.
4
What software is affected by CVE-2023-36862?
The affected software is macOS Ventura 13.5 and Apple iPadOS versions 13.0 to 13.5.
5
How was CVE-2023-36862 fixed?
CVE-2023-36862 was fixed in macOS Ventura 13.5 with additional code-signing restrictions.