CVE-2023-42846: Infoleak
Published Oct 25, 2023
·Updated
Automation. The issue was addressed with improved checks.
Credit
Talal Haj Bakry(Mysk Inc), Tommy Mysk@@mysk_co(Mysk Inc), Mingxuan Yang@@PPPF00L(360 Vulnerability Research Institute), (360 Vulnerability Research Institute), happybabywu(360 Vulnerability Research Institute), Guang Gong(360 Vulnerability Research Institute), Yiğit Can YILMAZ@@yilmazcanyigit, CVE-2023-42946, 이준성(Junsung Lee)(Cross Republic), 이준성(Junsung Lee), Pedro Ribeiro@@pedrib1337(Agile Information Security), Vitor Pedreira@@0xvhp_(Agile Information Security), Kirin@@Pwnrin(SecuRing), Wojciech Regula(SecuRing), (Computer Science), Cristian Dinca(Computer Science), Romania, Bistrit Dahal, JZ, Linus Henze(Pinauten GmbH), Mickey Jin@@patch1t, Grzegorz Riegel, Adam M., Csaba Fitzl@@theevilbit(Offensive Security), Michael (Biscuit) Thomas - @social.lol@@biscuit, CVE-2023-42823, an anonymous researcher, inooo, Alex Renda, Claire Houston, Kacper Kwapisz@@KKKas_, Adis Alic, Sam Lakmaker, Ting Ding, James Mancz, Omar Shibli, Lorenzo Cavallaro, Harry Lewandowski, Abhay Kailasia@@abhay_kailasia(Lakshmi Narain College Of Technology Bhopal India), Peter Nguyễn Vũ Hoàng@@peternguyen14(STAR Labs SG Pte), Tomi Tokics@@tomitokics(iTomsn0w), Zhipeng Huo@@R3dF09(Tencent Security Xuanwu Lab), Noah Roskin-Frazee, Pr
Affected Software
12 affected componentsFixes available
Apple tvOS<17.1
17.1
Apple WatchOS<10.1
10.1
Apple iOS<17.1
17.1
Apple iPadOS<17.1
17.1
Apple iOS<16.7.2
16.7.2
Apple iPadOS<16.7.2
16.7.2
Apple iPadOS<16.7.2
Apple iPadOS>=17.0<17.1
Apple iPhone OS<16.7.2
Apple iPhone OS>=17.0<17.1
Apple tvOS<17.1
Apple WatchOS<10.1
Event History
Oct 25, 2023
Data Sourced
via Apple·12:00 AM
DescriptionWeaknessAffected Software
Updated
via Apple·12:00 AM
DescriptionWeakness
Updated
via Apple·12:00 AM
DescriptionWeaknessAffected Software
CVE Published
via MITRE·06:31 PM
Data Sourced
via MITRE·06:31 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID of this issue?
The vulnerability ID of this issue is CVE-2023-42846.
2
What is the software affected by this vulnerability?
The software affected by this vulnerability includes watchOS, iOS, iPadOS, and tvOS.
3
How was this vulnerability fixed?
This vulnerability was fixed by removing the vulnerable code.
4
What versions of the affected software are fixed?
Versions 10.1 of watchOS, 16.7.2 and 17.1 of iOS and iPadOS, and 17.1 of tvOS are fixed.
5
Can a device be passively tracked by its Wi-Fi MAC address?
Yes, a device may be passively tracked by its Wi-Fi MAC address.