CVE-2023-40428: Use After Free
Accessibility. This issue was addressed with improved redaction of sensitive information.
Other sources
Airport. A permissions issue was addressed with improved redaction of sensitive information.
— Apple
App Store. The issue was addressed with improved handling of protocols.
— Apple
Apple Neural Engine. A use-after-free issue was addressed with improved memory management.
— Apple
Apple Neural Engine. An out-of-bounds read was addressed with improved input validation.
— Apple
Apple Neural Engine. The issue was addressed with improved handling of caches.
— Apple
Credit
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2023-40529
- CVE-2023-40384
- CVE-2023-40448
- CVE-2023-40432
- CVE-2023-41174
- CVE-2023-40409
- CVE-2023-40412
- CVE-2023-42871
- CVE-2023-41071
- CVE-2023-40399
- CVE-2023-40410
- CVE-2023-42872
- CVE-2023-42925
- CVE-2023-38612
- CVE-2023-32361
- CVE-2023-41232
- CVE-2023-35984
- CVE-2023-41065
- CVE-2023-38596
- CVE-2023-40420
- CVE-2023-40528
- CVE-2023-32396
- CVE-2023-41069
- CVE-2023-41980
- CVE-2023-40395
- CVE-2023-40431
- CVE-2023-40391
- CVE-2023-40441
- CVE-2023-40434
- CVE-2023-40396
- CVE-2023-41995
- CVE-2023-42870
- CVE-2023-41974
- CVE-2023-41981
- CVE-2023-41984
- CVE-2023-40429
- CVE-2023-41060
- CVE-2023-40400
- CVE-2023-40454
- CVE-2023-41073
- CVE-2023-40403
- CVE-2023-40427
- CVE-2023-42957
- CVE-2023-41068
- CVE-2023-41986
- CVE-2023-40401
- CVE-2023-42949
- CVE-2023-40456
- CVE-2023-40520
- CVE-2023-42934
- CVE-2023-41063
- CVE-2023-40422
- CVE-2023-35990
- CVE-2023-40417
- CVE-2023-40452
- CVE-2023-41070
- CVE-2023-40419
- CVE-2023-40428
- CVE-2023-41968
- CVE-2023-40424
- CVE-2023-39434
- CVE-2023-40414
- CVE-2023-41074
- CVE-2023-35074
- CVE-2023-32359
- CVE-2023-40385
- CVE-2023-42833
- CVE-2023-38610
- CVE-2023-42969
- CVE-2023-42961
- CVE-2023-40393
- CVE-2023-42977
- CVE-2023-42973
- CVE-2023-38614
- CVE-2023-42970
- CVE-2023-42875
Frequently Asked Questions
What is CVE-2023-40428?
CVE-2023-40428 is a vulnerability in Siri that has been addressed with improved handling of caches.
Which software versions are affected by CVE-2023-40428?
The vulnerability affects Apple iOS and iPadOS versions up to, but not including, version 17.
How can I fix CVE-2023-40428?
To fix CVE-2023-40428, make sure you update your Apple iOS and iPadOS to version 17 or higher.
What did Apple do to address CVE-2023-40428?
Apple addressed CVE-2023-40428 by improving the handling of caches in Siri.
Where can I find more information about CVE-2023-40428?
You can find more information about CVE-2023-40428 on the Apple support website: https://support.apple.com/en-us/HT213938