CVE-2023-42823
Published Oct 25, 2023
·Updated
Automation. The issue was addressed with improved checks.
Credit
CVE-2023-42823, Michael (Biscuit) Thomas - @social.lol@@biscuit, JZ, Mickey Jin@@patch1t, Talal Haj Bakry(Mysk Inc), Tommy Mysk@@mysk_co(Mysk Inc), Mingxuan Yang@@PPPF00L(360 Vulnerability Research Institute), (360 Vulnerability Research Institute), happybabywu(360 Vulnerability Research Institute), Guang Gong(360 Vulnerability Research Institute), Yiğit Can YILMAZ@@yilmazcanyigit, CVE-2023-42946, 이준성(Junsung Lee)(Cross Republic), 이준성(Junsung Lee), Pedro Ribeiro@@pedrib1337(Agile Information Security), Vitor Pedreira@@0xvhp_(Agile Information Security), Adam M., Csaba Fitzl@@theevilbit(Offensive Security), Linus Henze(Pinauten GmbH), Grzegorz Riegel, Kirin@@Pwnrin(SecuRing), Wojciech Regula(SecuRing), (Computer Science), Cristian Dinca(Computer Science), Romania, Bistrit Dahal, Tomi Tokics@@tomitokics(iTomsn0w), an anonymous researcher, inooo, Alex Renda, Claire Houston, Kacper Kwapisz@@KKKas_, Zhipeng Huo@@R3dF09(Tencent Security Xuanwu Lab), Noah Roskin-Frazee, Pr, Peter Nguyễn Vũ Hoàng@@peternguyen14(STAR Labs SG Pte), Adis Alic, Sam Lakmaker, Ting Ding, James Mancz, Omar Shibli, Lorenzo Cavallaro, Harry Lewandowski, Abhay Kailasia@@abhay_kailasia(Lakshmi Narain College Of Technology Bhopal India)
Affected Software
18 affected componentsFixes available
Apple macOS Sonoma<14.1
14.1
Apple tvOS<17.1
17.1
Apple WatchOS<10.1
10.1
Apple macOS Monterey<12.7.1
12.7.1
Apple macOS Ventura<13.6.1
13.6.1
Apple iOS<17.1
17.1
Apple iPadOS<17.1
17.1
Apple iOS<16.7.2
16.7.2
Apple iPadOS<16.7.2
16.7.2
Apple iPadOS<16.7.2
Apple iPadOS=17.0
Apple iPhone OS<16.7.2
Apple iPhone OS=17.0
Apple macOS>=12.0<12.7.1
Apple macOS>=13.0<13.6.1
Apple macOS=14.0
Apple tvOS<17.1
Apple WatchOS<10.1
Event History
Oct 25, 2023
Data Sourced
via Apple·12:00 AM
DescriptionWeaknessAffected Software
Updated
via Apple·12:00 AM
DescriptionWeakness
Updated
via Apple·12:00 AM
DescriptionWeaknessAffected Software
Feb 21, 2024
CVE Published
via MITRE·06:41 AM
Data Sourced
via MITRE·06:41 AM
DescriptionWeakness
Data Sourced
via NVD·07:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2023-42823?
CVE-2023-42823 is categorized as a high severity vulnerability due to its potential impact on application security.
2
How do I fix CVE-2023-42823?
To mitigate CVE-2023-42823, upgrade to the latest software versions listed, such as watchOS 10.1 or iOS 17.1.
3
Which products are affected by CVE-2023-42823?
CVE-2023-42823 affects multiple Apple products including macOS Monterey, iOS, iPadOS, tvOS, and watchOS.
4
What types of issues does CVE-2023-42823 address?
CVE-2023-42823 addresses issues related to insufficient logging and sanitization that could allow unauthorized access.
5
When was CVE-2023-42823 disclosed?
CVE-2023-42823 was disclosed by Apple in a security update along with a list of affected versions and fixes.