CVE-2023-40418: Input Validation
An authentication issue was addressed with improved state management. This issue is fixed in watchOS 10. An Apple Watch Ultra may not lock when using the Depth app.
Other sources
App Store. The issue was addressed with improved handling of protocols.
— Apple
Apple Neural Engine. A use-after-free issue was addressed with improved memory management.
— Apple
Apple Neural Engine. An out-of-bounds read was addressed with improved input validation.
— Apple
Apple Neural Engine. The issue was addressed with improved memory handling.
— Apple
AuthKit. The issue was addressed with improved handling of caches.
— Apple
Credit
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2023-40448
- CVE-2023-40432
- CVE-2023-41174
- CVE-2023-40409
- CVE-2023-40412
- CVE-2023-41071
- CVE-2023-40399
- CVE-2023-40410
- CVE-2023-32361
- CVE-2023-35984
- CVE-2023-41065
- CVE-2023-38596
- CVE-2023-40420
- CVE-2023-40528
- CVE-2023-32396
- CVE-2023-40395
- CVE-2023-40396
- CVE-2023-41981
- CVE-2023-41984
- CVE-2023-40429
- CVE-2023-40400
- CVE-2023-40454
- CVE-2023-41073
- CVE-2023-40403
- CVE-2023-40427
- CVE-2023-42957
- CVE-2023-41068
- CVE-2023-40418
- CVE-2023-42949
- CVE-2023-40456
- CVE-2023-40520
- CVE-2023-35990
- CVE-2023-40417
- CVE-2023-40452
- CVE-2023-41070
- CVE-2023-40419
- CVE-2023-41968
- CVE-2023-40424
- CVE-2023-39434
- CVE-2023-40414
- CVE-2023-41074
- CVE-2023-35074
- CVE-2023-42970
- CVE-2023-42875
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2023-40418.
What is the title of this vulnerability?
The title of this vulnerability is 'Passcode. An authentication issue was addressed with improved state management.'
What was addressed in this vulnerability?
This vulnerability addressed an authentication issue with improved state management.
Which software is affected by this vulnerability?
The watchOS version 10 and below from Apple are affected by this vulnerability.
How can I fix this vulnerability?
To fix this vulnerability, update your watchOS to a version higher than 10.