CVE-2023-42861: Race Condition
A logic issue was addressed with improved state management. This issue is fixed in macOS Sonoma 14.1. An attacker with knowledge of a standard user's credentials can unlock another standard user's locked screen on the same Mac.
Other sources
AVEVideoEncoder. The issue was addressed with improved memory handling.
— Apple
Core Data. An issue was addressed with improved validation of environment variables.
— Apple
CoreMedia. An out-of-bounds write issue was addressed with improved input validation.
— Apple
CoreMedia. The issue was addressed with improved checks.
— Apple
Finder. This issue was addressed through improved state management.
— Apple
Credit
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2023-30774
- CVE-2023-40444
- CVE-2023-42952
- CVE-2023-42945
- CVE-2023-41072
- CVE-2023-42857
- CVE-2023-40449
- CVE-2023-42823
- CVE-2023-41989
- CVE-2023-42854
- CVE-2023-40413
- CVE-2023-42834
- CVE-2023-42844
- CVE-2023-42953
- CVE-2023-40416
- CVE-2023-42848
- CVE-2023-40423
- CVE-2023-38403
- CVE-2023-42849
- CVE-2023-42850
- CVE-2023-40446
- CVE-2023-42942
- CVE-2023-42861
- CVE-2023-42935
- CVE-2023-40408
- CVE-2023-40405
- CVE-2023-28826
- CVE-2023-42856
- CVE-2023-40404
- CVE-2023-42859
- CVE-2023-42877
- CVE-2023-42840
- CVE-2023-42853
- CVE-2023-42860
- CVE-2023-42889
- CVE-2023-42847
- CVE-2023-42845
- CVE-2023-42841
- CVE-2023-42873
- CVE-2023-42838
- CVE-2023-42835
- CVE-2023-41977
- CVE-2023-42438
- CVE-2023-42836
- CVE-2023-42839
- CVE-2023-42878
- CVE-2023-41982
- CVE-2023-41997
- CVE-2023-41988
- CVE-2023-42946
- CVE-2023-36191
- CVE-2023-40421
- CVE-2023-42842
- CVE-2023-4733
- CVE-2023-4734
- CVE-2023-4735
- CVE-2023-4736
- CVE-2023-4738
- CVE-2023-4750
- CVE-2023-4751
- CVE-2023-4752
- CVE-2023-4781
- CVE-2023-41254
- CVE-2023-40447
- CVE-2023-41976
- CVE-2023-42852
- CVE-2023-42843
- CVE-2023-41983
- CVE-2023-41975
- CVE-2023-42858
- CVE-2024-27805
- CVE-2024-27817
- CVE-2024-27831
- CVE-2024-27827
- CVE-2024-27789
- CVE-2024-27799
- CVE-2024-27840
- CVE-2024-27823
- CVE-2024-27810
- CVE-2024-27800
- CVE-2024-27802
- CVE-2024-27885
- CVE-2024-27824
- CVE-2024-23296
- CVE-2024-27843
- CVE-2024-27855
- CVE-2024-27806
- CVE-2024-27798
- CVE-2024-27847
- CVE-2024-27796
- CVE-2024-40771
Frequently Asked Questions
What is CVE-2023-42861?
CVE-2023-42861 is a logic issue in the Login Window of macOS Sonoma 14.1, which allows an attacker to unlock another user's locked screen on the same Mac.
How can an attacker exploit CVE-2023-42861?
An attacker with knowledge of a standard user's credentials can unlock another standard user's locked screen on the same Mac.
What is the severity of CVE-2023-42861?
The severity of CVE-2023-42861 is moderate.
How can I fix CVE-2023-42861?
To fix CVE-2023-42861, update your macOS to Sonoma 14.1 or later.
Where can I find more information about CVE-2023-42861?
For more information about CVE-2023-42861, you can refer to the following resources: [Apple Support](https://support.apple.com/en-us/HT213984), [Full Disclosure Mailing List](http://seclists.org/fulldisclosure/2023/Oct/24), [Apple Security Updates](https://support.apple.com/kb/HT213984).