CVE-2023-40401: Buffer Overflow
Accessibility. This issue was addressed with improved redaction of sensitive information.
Other sources
Airport. A permissions issue was addressed with improved redaction of sensitive information.
— Apple
AMD. A buffer overflow issue was addressed with improved memory handling.
— Apple
AMD. The issue was addressed with improved memory handling.
— Apple
App Store. The issue was addressed with improved handling of protocols.
— Apple
Apple Neural Engine. A use-after-free issue was addressed with improved memory management.
— Apple
Credit
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2023-40384
- CVE-2023-32377
- CVE-2023-38615
- CVE-2023-40448
- CVE-2023-40432
- CVE-2023-42871
- CVE-2023-40399
- CVE-2023-40410
- CVE-2023-42872
- CVE-2023-42929
- CVE-2023-42925
- CVE-2023-38612
- CVE-2023-32361
- CVE-2023-35984
- CVE-2023-40402
- CVE-2023-40426
- CVE-2023-42876
- CVE-2023-41065
- CVE-2023-29497
- CVE-2023-38596
- CVE-2023-42943
- CVE-2023-40406
- CVE-2023-40420
- CVE-2023-40528
- CVE-2023-40438
- CVE-2023-41994
- CVE-2023-40407
- CVE-2023-32396
- CVE-2023-42933
- CVE-2023-41980
- CVE-2023-40411
- CVE-2023-40395
- CVE-2023-40391
- CVE-2023-40441
- CVE-2023-42959
- CVE-2023-23495
- CVE-2023-40434
- CVE-2023-38586
- CVE-2023-40436
- CVE-2023-40396
- CVE-2023-41995
- CVE-2023-42870
- CVE-2023-41981
- CVE-2023-41984
- CVE-2023-40429
- CVE-2023-41060
- CVE-2023-41067
- CVE-2023-40400
- CVE-2023-40454
- CVE-2023-41073
- CVE-2023-40403
- CVE-2023-40427
- CVE-2023-42957
- CVE-2023-32421
- CVE-2023-42826
- CVE-2023-42918
- CVE-2023-41986
- CVE-2023-40455
- CVE-2023-40386
- CVE-2023-38408
- CVE-2023-40401
- CVE-2023-40393
- CVE-2023-42949
- CVE-2023-42934
- CVE-2023-37448
- CVE-2023-38607
- CVE-2023-41987
- CVE-2023-41063
- CVE-2023-40422
- CVE-2023-39233
- CVE-2023-40388
- CVE-2023-35990
- CVE-2023-40417
- CVE-2023-40452
- CVE-2023-40430
- CVE-2023-41996
- CVE-2023-41078
- CVE-2023-41070
- CVE-2023-40541
- CVE-2023-41079
- CVE-2023-40443
- CVE-2023-41968
- CVE-2023-40450
- CVE-2023-42948
- CVE-2023-40424
- CVE-2023-39434
- CVE-2023-40414
- CVE-2023-41074
- CVE-2023-35074
- CVE-2023-41993
- CVE-2023-32359
- CVE-2023-40385
- CVE-2023-42833
- CVE-2023-38610
- CVE-2023-41066
- CVE-2023-41979
- CVE-2023-40449
- CVE-2023-42823
- CVE-2023-42854
- CVE-2023-40413
- CVE-2023-42844
- CVE-2023-41077
- CVE-2023-40416
- CVE-2023-42848
- CVE-2023-40423
- CVE-2023-38403
- CVE-2023-42849
- CVE-2023-40446
- CVE-2023-42942
- CVE-2023-42856
- CVE-2023-42859
- CVE-2023-42877
- CVE-2023-42840
- CVE-2023-42889
- CVE-2023-42853
- CVE-2023-42860
- CVE-2023-42841
- CVE-2023-42873
- CVE-2023-36191
- CVE-2023-40421
- CVE-2023-41254
- CVE-2023-41975
- CVE-2023-42858
- CVE-2023-40529
- CVE-2023-41174
- CVE-2023-40409
- CVE-2023-40412
- CVE-2023-41071
- CVE-2023-41232
- CVE-2023-41069
- CVE-2023-40431
- CVE-2023-41974
- CVE-2023-41068
- CVE-2023-40456
- CVE-2023-40520
- CVE-2023-40419
- CVE-2023-40428
- CVE-2023-41992
- CVE-2023-41991
- CVE-2023-42969
- CVE-2023-42961
- CVE-2023-42977
- CVE-2023-42973
- CVE-2023-38614
- CVE-2023-42970
- CVE-2023-42875
- CVE-2023-42981
- CVE-2023-42982
- CVE-2023-42983
- CVE-2023-40425
- CVE-2023-41076
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2023-40401.
What is the impact of vulnerability CVE-2023-40401?
The impact of vulnerability CVE-2023-40401 is that an attacker may be able to access passkeys without authentication.
What software versions are affected by CVE-2023-40401?
CVE-2023-40401 affects macOS Ventura versions up to but excluding 13.6.1.
How was vulnerability CVE-2023-40401 addressed?
Vulnerability CVE-2023-40401 was addressed with additional permissions checks.
Where can I find more information about vulnerability CVE-2023-40401?
You can find more information about vulnerability CVE-2023-40401 at the following references: [Support Article](https://support.apple.com/en-us/HT213985), [Security Mailing List](http://seclists.org/fulldisclosure/2023/Oct/26), [Apple Knowledge Base Article](https://support.apple.com/kb/HT213985).