CVE-2023-38136
Published Jul 24, 2023
·Updated
Accessibility. A privacy issue was addressed with improved private data redaction for log entries.
Credit
Mohamed GHANNAM@@_simo36, pattern-f@@pattern_F_(Ant Security Light), Nick Brook, Kirin@@Pwnrin, Wojciech Regula(SecuRing), Kirin@@Pwnrin(SecuRing), (SecuRing), found by OSS-Fuzz, Zweig(Kunlun Lab), 香农的三蹦子(Pangu Lab), an anonymous researcher, Pan ZhenPeng@@Peterpan0927(STAR Labs SG Pte), Peter Nguyễn Vũ Hoàng@@peternguyen14(STAR Labs SG Pte), Certik Skyfall Team, Valentin Pashkov(Kaspersky), Mikhail Vinogradov(Kaspersky), Georgy Kucherin@@kucher1n(Kaspersky), Leonid Bezvershenko@@bzvr_(Kaspersky), (Kaspersky), Boris Larin@@oct0xor(Kaspersky), Kaitao Xie(Alibaba Group), Xiaolong Bai(Alibaba Group), Certik Skyfall Team(Ant Security Light), Sei K., Zhipeng Huo@@R3dF09(Tencent Security Xuanwu Lab), Noah Roskin-Frazee, Thijs Alkemade(Computest Sector 7), Adam M., Johan Carlsson (joaxcar), Hritvik Taneja, Jason Kim, Jie Jeff Xu, Stephan van Schaik, Daniel Genkin, Yuval Yarom, Narendra Bhati (twitter.com/imnarendrabhati)(Suma Soft Pvt), Pune - India(TU Wien), Valentino Dalla Valle(TU Wien), Pedro Bernardo(TU Wien), Marco Squarcina(TU Wien), (TU Wien), Lorenzo Veronese(TU Wien), Pune - India, Yuhao Hu, Jiming Wang, Jikai Ren, Anonymous(Trend Micro Zero Day Initiative), Francisco Alonso@@revskills, Junsung Lee, 이준성(Junsung Lee)(Cross Republic), Apple, YeongHyeon Choi@@hyeon101010
Affected Software
7 affected componentsFixes available
Apple WatchOS<9.6
9.6
Apple iPhone OS<16.6
Apple WatchOS<9.6
Apple Ipad Os<16.6
Apple iOS<16.6
16.6
Apple iPadOS<16.6
16.6
Apple iPadOS<16.6
Event History
Jul 24, 2023
Data Sourced
via Apple·12:00 AM
DescriptionWeaknessAffected Software
Updated
via Apple·12:00 AM
Description
Updated
via Apple·12:00 AM
DescriptionWeakness
Jul 27, 2023
CVE Published
via MITRE·12:30 AM
Data Sourced
via MITRE·12:30 AM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2023-38136.
2
What is the severity of CVE-2023-38136?
The severity of CVE-2023-38136 is high with a score of 7.8.
3
How was the issue addressed?
The issue was addressed with improved memory handling.
4
Which software versions are affected by CVE-2023-38136?
CVE-2023-38136 affects Apple iOS versions up to but not including 16.6, Apple iPadOS versions up to but not including 16.6, and Apple watchOS versions up to but not including 9.6.
5
How do I fix CVE-2023-38136?
To fix CVE-2023-38136, update your Apple iOS device to version 16.6, update your Apple iPadOS device to version 16.6, and update your Apple watchOS device to version 9.6.