CVE-2023-40529
Published Sep 18, 2023
·Updated
Accessibility. This issue was addressed with improved redaction of sensitive information.
Credit
Abhay Kailasia@@abhay_kailasia(Lakshmi Narain College Of Technology Bhopal), Adam M., w0wbox, pattern-f@@pattern_F_(Ant Security Light), Mohamed GHANNAM@@_simo36, Ye Zhang@@VAR10CK(Baidu Security), Tim Michaud@@TimGMichaud(Moveworks), Mickey Jin@@patch1t, Wojciech Reguła@@_r3ggi, Kirin@@Pwnrin, Chris Ross (Zoom), Csaba Fitzl@@theevilbit(Offensive Security), Liang Wei(PixiePoint Security), zer0k, Noah Roskin-Frazee, Professor Jason Lau (ZeroClicks.ai Lab), Will Brattain at Trail(Bits), 이준성(Junsung Lee)(Cross Republic), Kirin@@Pwnrin(NorthSea), Zhice Yang (ShanghaiTech University), Certik Skyfall Team, Antonio Zekic@@antoniozekic(Dataflow Security), Ron Masas(Imperva), Mikko Kenttälä )@@Turmio_(SensorFu), Certik Skyfall Team(Ant Security Light), Zweig(Kunlun Lab), Félix Poulin-Bélanger, Linus Henze(Pinauten GmbH), Pan ZhenPeng@@Peterpan0927(STAR Labs SG Pte), Michael (Biscuit) Thomas, 张师傅(@京东蓝军), Joseph Ravichandran@@0xjprx(MIT CSAIL), Sei K., Zhipeng Huo@@R3dF09(Tencent Security Xuanwu Lab), Dohyun Lee@@l33d0hyun(PK Security), Adam M.(SecuRing), (SecuRing), Wojciech Regula(SecuRing), Adam M.(BreakPoint Security Research), (BreakPoint Security Research), Ron Masas(BreakPoint Security Research), Gergely Kalman@@gergely_kalman, weize she, an anonymous researcher, Berke Kırbaş, Harsh Jaiswal, Tomi Tokics@@tomitokics(iTomsn0w), Adriatik Raci(Sentry Cybersecurity), Narendra Bhati (twitter.com/imnarendrabhati)(Suma Soft Pvt), Pune (India), Kenneth Chew, Yiğit Can YILMAZ@@yilmazcanyigit, Arsenii Kostromin (0x3c3e), James Hutchins, Brian McNulty(Offensive Security), Arsenii Kostromin (0x3c3e)(Offensive Security), Joshua Jewett@@JoshJewett33(Offensive Security), (Offensive Security), Francisco Alonso@@revskills(PK Security), (PK Security), Francisco Alonso@@revskills, Jie Ding@@Lime(HKUS3 Lab), Dong Jun Kim@@smlijun(AbyssLab), Jong Seong Kim@@nevul37(AbyssLab), zhunki, 이준성(Junsung Lee), Claire Houston, Anonymous, Wang Yu(Cyberserval)
Affected Software
4 affected componentsFixes available
Apple iOS<17
17
Apple iPadOS<17
17
Apple iPadOS<17.0
Apple iPhone OS<17.0
Event History
Sep 18, 2023
Data Sourced
via Apple·12:00 AM
DescriptionWeaknessAffected Software
Jan 10, 2024
CVE Published
via MITRE·10:03 PM
Data Sourced
via MITRE·10:03 PM
DescriptionWeakness
Data Sourced
via NVD·10:15 PM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2023-40529?
The severity of CVE-2023-40529 is classified as high due to potential unauthorized access to sensitive information by individuals with physical access to the device.
2
How do I fix CVE-2023-40529?
To fix CVE-2023-40529, users should update their devices to iOS 17 or iPadOS 17, where the issue has been addressed.
3
Who is affected by CVE-2023-40529?
CVE-2023-40529 affects users of Apple iOS and iPadOS versions prior to 17.
4
What devices are impacted by CVE-2023-40529?
Devices impacted by CVE-2023-40529 include iPhones and iPads running versions of iOS and iPadOS below 17.
5
What type of vulnerability is CVE-2023-40529?
CVE-2023-40529 is an accessibility vulnerability that involves improper redaction of sensitive information when using VoiceOver.