CVE-2023-38612: Input Validation
Published Sep 18, 2023
·Updated
Accessibility. This issue was addressed with improved redaction of sensitive information.
Credit
Chris Ross (Zoom), pattern-f@@pattern_F_(Ant Security Light), Mohamed GHANNAM@@_simo36, Ye Zhang@@VAR10CK(Baidu Security), Tim Michaud@@TimGMichaud(Moveworks), Liang Wei(PixiePoint Security), JeongOhKyea(Theori), 이준성(Junsung Lee)(Cross Republic), Mickey Jin@@patch1t, Pan ZhenPeng@@Peterpan0927(STAR Labs SG Pte), Linus Henze(Pinauten GmbH), Bill Marczak(The Citizen Lab at The University of Toronto's Munk School), Maddie Stone(Google's Threat Analysis Group), Zhipeng Huo@@R3dF09(Tencent Security Xuanwu Lab), Dohyun Lee@@l33d0hyun(PK Security), Adam M.(SecuRing), (SecuRing), Wojciech Regula(SecuRing), Certik Skyfall Team, Yiğit Can YILMAZ@@yilmazcanyigit, Kirin@@Pwnrin, James Hutchins, Wojciech Reguła@@_r3ggi, Csaba Fitzl@@theevilbit(Offensive Security), zer0k, Adam M., Noah Roskin-Frazee, Professor Jason Lau (ZeroClicks.ai Lab), Will Brattain at Trail(Bits), Kirin@@Pwnrin(NorthSea), Zhice Yang (ShanghaiTech University), Antonio Zekic@@antoniozekic(Dataflow Security), Ron Masas(Imperva), Mikko Kenttälä )@@Turmio_(SensorFu), Certik Skyfall Team(Ant Security Light), Zweig(Kunlun Lab), Félix Poulin-Bélanger, Michael (Biscuit) Thomas, 张师傅(@京东蓝军), Joseph Ravichandran@@0xjprx(MIT CSAIL), Sei K., Adam M.(BreakPoint Security Research), (BreakPoint Security Research), Ron Masas(BreakPoint Security Research), Gergely Kalman@@gergely_kalman, weize she, an anonymous researcher, Berke Kırbaş, Harsh Jaiswal, Tomi Tokics@@tomitokics(iTomsn0w), Adriatik Raci(Sentry Cybersecurity), Narendra Bhati (twitter.com/imnarendrabhati)(Suma Soft Pvt), Pune (India), Kenneth Chew, Arsenii Kostromin (0x3c3e), Abhay Kailasia@@abhay_kailasia(Lakshmi Narain College Of Technology Bhopal), Brian McNulty(Offensive Security), Arsenii Kostromin (0x3c3e)(Offensive Security), Joshua Jewett@@JoshJewett33(Offensive Security), (Offensive Security), Francisco Alonso@@revskills(PK Security), (PK Security), Francisco Alonso@@revskills, Jie Ding@@Lime(HKUS3 Lab), Dong Jun Kim@@smlijun(AbyssLab), Jong Seong Kim@@nevul37(AbyssLab), zhunki, 이준성(Junsung Lee), Claire Houston, Anonymous, Wang Yu(Cyberserval), w0wbox, Koh M. Nakagawa@@tsunek0h, Yishu Wang, Cristian Dinca(Computer Science), Romania, Halle Winkler, Politepix@@hallewinkler, Noah Roskin-Frazee(Offensive Security), Pr(Offensive Security), Murray Mike, (Ant Security Light), Ferdous Saljooki@@malwarezoo(Jamf Software), Meng Zhang (鲸落)(NorthSea), Brian McNulty(Texts), (Texts), Kishan Bagaria(Texts), Michael DePlante@@izobashi(Trend Micro Zero Day Initiative), baba yaga, Serkan Erayabakan(George Mason University), David Kotval(George Mason University), Akincibor(George Mason University), Sina Ahmadi(George Mason University), Billy Tabrizi, Kirin@@Pwnrin(SecuRing), Luan Herrera@@lbherrera_, Noah Roskin-Frazee (ZeroClicks.ai Lab), James Duffy (mangoSecure), Ron Masas(BreakPoint), Thijs Alkemade@@xnyhps(Computest Sector 7), Andrew Haggard, (AbyssLab), An anonymous researcher(MacEnhance), Jeremy Legendre(MacEnhance), Felix Kratz, ABC Research s.r.o.
Affected Software
11 affected componentsFixes available
Apple macOS Sonoma<14
14
Apple macOS Monterey<12.7
12.7
Apple macOS Ventura<13.6
13.6
Apple iOS<16.7
16.7
Apple iPadOS<16.7
16.7
Apple iOS<17
17
Apple iPadOS<17
17
Apple iPadOS<16.7
Apple iPhone OS<16.7
Apple macOS<12.7
Apple macOS>=13.0<13.6
Event History
Sep 18, 2023
Data Sourced
via Apple·12:00 AM
DescriptionWeaknessAffected Software
Updated
via Apple·12:00 AM
DescriptionWeakness
Sep 21, 2023
Updated
via Apple·12:00 AM
Affected Software
Updated
via Apple·12:00 AM
DescriptionWeaknessAffected Software
Sep 26, 2023
Updated
via Apple·12:00 AM
DescriptionWeaknessAffected Software
Updated
via Apple·12:00 AM
Affected Software
Jan 10, 2024
CVE Published
via MITRE·10:03 PM
Data Sourced
via MITRE·10:03 PM
DescriptionWeakness
Data Sourced
via NVD·10:15 PM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2023-38612?
CVE-2023-38612 is considered a high-severity vulnerability due to its potential to expose sensitive information.
2
How do I fix CVE-2023-38612?
To fix CVE-2023-38612, update your Apple macOS Monterey to version 12.7, macOS Ventura to version 13.6, or upgrade to macOS Sonoma version 14.
3
Which Apple products are affected by CVE-2023-38612?
CVE-2023-38612 affects multiple Apple products including macOS Monterey, iOS, iPadOS, and macOS Ventura.
4
What type of vulnerability is CVE-2023-38612?
CVE-2023-38612 is a permissions issue that also addresses buffer overflow vulnerabilities.
5
Is CVE-2023-38612 only for recent versions of macOS and iOS?
Yes, CVE-2023-38612 primarily affects Apple devices running older versions of macOS Monterey, iOS, and iPadOS, up to specific versions.