CVE-2023-40520: Use After Free
Accessibility. This issue was addressed with improved redaction of sensitive information.
Other sources
Airport. A permissions issue was addressed with improved redaction of sensitive information.
— Apple
App Store. The issue was addressed with improved handling of protocols.
— Apple
Apple Neural Engine. A use-after-free issue was addressed with improved memory management.
— Apple
Apple Neural Engine. An out-of-bounds read was addressed with improved input validation.
— Apple
Apple Neural Engine. The issue was addressed with improved handling of caches.
— Apple
Credit
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2023-40384
- CVE-2023-40448
- CVE-2023-40432
- CVE-2023-41174
- CVE-2023-40409
- CVE-2023-40412
- CVE-2023-41071
- CVE-2023-40399
- CVE-2023-40410
- CVE-2023-32361
- CVE-2023-35984
- CVE-2023-41065
- CVE-2023-38596
- CVE-2023-40420
- CVE-2023-40528
- CVE-2023-32396
- CVE-2023-40395
- CVE-2023-40391
- CVE-2023-40396
- CVE-2023-41981
- CVE-2023-41984
- CVE-2023-40429
- CVE-2023-40400
- CVE-2023-40454
- CVE-2023-41073
- CVE-2023-40403
- CVE-2023-40427
- CVE-2023-41068
- CVE-2023-42949
- CVE-2023-40456
- CVE-2023-40520
- CVE-2023-41063
- CVE-2023-40452
- CVE-2023-40419
- CVE-2023-41968
- CVE-2023-41074
- CVE-2023-35074
- CVE-2023-40414
- CVE-2023-42957
- CVE-2023-40418
- CVE-2023-35990
- CVE-2023-40417
- CVE-2023-41070
- CVE-2023-40424
- CVE-2023-39434
- CVE-2023-40529
- CVE-2023-42871
- CVE-2023-42872
- CVE-2023-42925
- CVE-2023-38612
- CVE-2023-41232
- CVE-2023-41069
- CVE-2023-41980
- CVE-2023-40431
- CVE-2023-40441
- CVE-2023-40434
- CVE-2023-41995
- CVE-2023-42870
- CVE-2023-41974
- CVE-2023-41060
- CVE-2023-41986
- CVE-2023-40401
- CVE-2023-42934
- CVE-2023-40422
- CVE-2023-40428
- CVE-2023-32359
- CVE-2023-40385
- CVE-2023-42833
- CVE-2023-38610
- CVE-2023-42875
- CVE-2023-42970
- CVE-2023-42969
- CVE-2023-42961
- CVE-2023-40393
- CVE-2023-42977
- CVE-2023-42973
- CVE-2023-38614
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2023-40520.
What is the affected software?
The affected software includes Apple tvOS (up to version 17), Apple iOS (up to version 17), Apple iPadOS (up to version 17), and Apple watchOS (up to version 10).
What is the remediation for this vulnerability?
The vulnerability was addressed with improved checks in the affected software versions.
Where can I find more information about this vulnerability?
You can find more information about this vulnerability on the Apple support website. Here are some references: [https://support.apple.com/en-us/HT213937](https://support.apple.com/en-us/HT213937), [https://support.apple.com/en-us/HT213936](https://support.apple.com/en-us/HT213936), [https://support.apple.com/en-us/HT213938](https://support.apple.com/en-us/HT213938).
How severe is this vulnerability?
The severity of this vulnerability is not specified in the provided information.