CVE-2023-42846: Infoleak
Automation. The issue was addressed with improved checks.
Other sources
Contacts. A privacy issue was addressed with improved private data redaction for log entries.
— Apple
Core Recents. The issue was resolved by sanitizing logging
— Apple
CoreAnimation. The issue was addressed with improved memory handling.
— Apple
FairPlay. The issue was addressed with improved bounds checks.
— Apple
Find My. A privacy issue was addressed with improved handling of files.
— Apple
Credit
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2023-42823
- CVE-2023-42953
- CVE-2023-42848
- CVE-2023-42942
- CVE-2023-42846
- CVE-2023-42873
- CVE-2023-42839
- CVE-2023-42946
- CVE-2023-40447
- CVE-2023-41976
- CVE-2023-42852
- CVE-2023-40413
- CVE-2023-42834
- CVE-2023-42849
- CVE-2023-40408
- CVE-2023-42878
- CVE-2023-41982
- CVE-2023-41997
- CVE-2023-41988
- CVE-2023-41254
- CVE-2023-42952
- CVE-2023-41072
- CVE-2023-42857
- CVE-2023-40449
- CVE-2023-42928
- CVE-2023-40416
- CVE-2023-40423
- CVE-2023-40446
- CVE-2023-42847
- CVE-2023-42845
- CVE-2023-42841
- CVE-2023-42951
- CVE-2023-42836
- CVE-2023-42855
- CVE-2023-40445
- CVE-2023-42843
- CVE-2023-42939
- CVE-2023-41983
- CVE-2023-41977
- CVE-2023-32359
Frequently Asked Questions
What is the vulnerability ID of this issue?
The vulnerability ID of this issue is CVE-2023-42846.
What is the software affected by this vulnerability?
The software affected by this vulnerability includes watchOS, iOS, iPadOS, and tvOS.
How was this vulnerability fixed?
This vulnerability was fixed by removing the vulnerable code.
What versions of the affected software are fixed?
Versions 10.1 of watchOS, 16.7.2 and 17.1 of iOS and iPadOS, and 17.1 of tvOS are fixed.
Can a device be passively tracked by its Wi-Fi MAC address?
Yes, a device may be passively tracked by its Wi-Fi MAC address.