CVE-2023-42855: Medium severity apple ios and ipados vulnerability
Automation. The issue was addressed with improved checks.
Other sources
Contacts. A privacy issue was addressed with improved private data redaction for log entries.
— Apple
Core Recents. The issue was resolved by sanitizing logging
— Apple
CoreAnimation. The issue was addressed with improved memory handling.
— Apple
FairPlay. The issue was addressed with improved bounds checks.
— Apple
Find My. A privacy issue was addressed with improved handling of files.
— Apple
Credit
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2023-42952
- CVE-2023-41072
- CVE-2023-42857
- CVE-2023-40449
- CVE-2023-42823
- CVE-2023-42928
- CVE-2023-40413
- CVE-2023-42834
- CVE-2023-42953
- CVE-2023-40416
- CVE-2023-42848
- CVE-2023-40423
- CVE-2023-42849
- CVE-2023-40446
- CVE-2023-42942
- CVE-2023-40408
- CVE-2023-42846
- CVE-2023-42847
- CVE-2023-42845
- CVE-2023-42841
- CVE-2023-42873
- CVE-2023-42951
- CVE-2023-42836
- CVE-2023-42839
- CVE-2023-42855
- CVE-2023-42878
- CVE-2023-41982
- CVE-2023-41997
- CVE-2023-41988
- CVE-2023-42946
- CVE-2023-40445
- CVE-2023-41254
- CVE-2023-40447
- CVE-2023-41976
- CVE-2023-42852
- CVE-2023-42843
- CVE-2023-42939
- CVE-2023-41983
Frequently Asked Questions
What is the severity of CVE-2023-42855?
CVE-2023-42855 is considered a moderate vulnerability that allows an attacker with physical access to potentially persist an Apple ID on an erased device.
How do I fix CVE-2023-42855?
To fix CVE-2023-42855, update your device to iOS 17.1 or iPadOS 17.1.
Who is affected by CVE-2023-42855?
CVE-2023-42855 affects users of Apple devices running iOS and iPadOS versions prior to 17.1.
What does CVE-2023-42855 exploit?
CVE-2023-42855 exploits issues with state management in the Setup Assistant on Apple devices.
Is there a workaround for CVE-2023-42855?
There is no known workaround for CVE-2023-42855 aside from upgrading to the latest software version.