CVE-2023-38564: Race Condition
Accounts. A privacy issue was addressed with improved private data redaction for log entries.
Other sources
AMD. A race condition was addressed with improved state handling.
— Apple
Apple Neural Engine. The issue was addressed with improved memory handling.
— Apple
AppleMobileFileIntegrity. A downgrade issue affecting Intel-based Mac computers was addressed with additional code-signing restrictions.
— Apple
AppSandbox. A logic issue was addressed with improved restrictions.
— Apple
Assets. This issue was addressed with improved data protection.
— Apple
Credit
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2023-40439
- CVE-2023-38616
- CVE-2023-34425
- CVE-2023-38580
- CVE-2023-36862
- CVE-2023-32364
- CVE-2023-35983
- CVE-2023-40392
- CVE-2023-42828
- CVE-2023-34241
- CVE-2023-28319
- CVE-2023-28320
- CVE-2023-28321
- CVE-2023-28322
- CVE-2023-32416
- CVE-2023-40437
- CVE-2023-32418
- CVE-2023-36854
- CVE-2022-3970
- CVE-2023-28200
- CVE-2023-38590
- CVE-2023-38598
- CVE-2023-36495
- CVE-2023-37285
- CVE-2023-38604
- CVE-2023-32734
- CVE-2023-32441
- CVE-2023-38261
- CVE-2023-38424
- CVE-2023-38425
- CVE-2023-32381
- CVE-2023-32433
- CVE-2023-35993
- CVE-2023-38410
- CVE-2023-38606
- CVE-2023-38603
- CVE-2023-38565
- CVE-2023-38593
- CVE-2023-40440
- CVE-2023-38258
- CVE-2023-38421
- CVE-2023-1916
- CVE-2023-38571
- CVE-2023-29491
- CVE-2023-38601
- CVE-2023-32444
- CVE-2023-2953
- CVE-2023-42829
- CVE-2023-38609
- CVE-2023-38259
- CVE-2023-38564
- CVE-2023-38602
- CVE-2023-42831
- CVE-2023-32442
- CVE-2023-32443
- CVE-2023-42832
- CVE-2023-32429
- CVE-2023-1801
- CVE-2023-32654
- CVE-2023-2426
- CVE-2023-2609
- CVE-2023-2610
- CVE-2023-38608
- CVE-2023-38605
- CVE-2023-40397
- CVE-2023-38572
- CVE-2023-38599
- CVE-2023-32445
- CVE-2023-38592
- CVE-2023-38594
- CVE-2023-38595
- CVE-2023-38600
- CVE-2023-38611
- CVE-2023-37450
- CVE-2023-42866
- CVE-2023-38597
- CVE-2023-38133
- CVE-2023-43000
Frequently Asked Questions
What is CVE-2023-38564?
CVE-2023-38564 is a vulnerability in PackageKit, a package manager for macOS, that allows an app to modify protected parts of the file system.
How severe is CVE-2023-38564?
CVE-2023-38564 has a severity rating of 7.5 (high).
How was CVE-2023-38564 fixed?
CVE-2023-38564 was fixed with improved checks in the macOS Ventura 13.5 update.
Which software versions are affected by CVE-2023-38564?
CVE-2023-38564 affects macOS Ventura versions up to, but excluding, 13.5.
Where can I find more information about CVE-2023-38564?
You can find more information about CVE-2023-38564 in the Apple support article at https://support.apple.com/en-us/HT213843.