CVE-2023-42874
Published Dec 11, 2023
·Updated
Accessibility. This issue was addressed with improved state management.
Credit
Don Clarke, Noah Roskin-Frazee, Pr, Kirin@@Pwnrin, Ivan Fratric(Google Project Zero), (Trend Micro Zero Day Initiative), Michael DePlante@@izobashi(Trend Micro Zero Day Initiative), Mickey Jin@@patch1t, an anonymous researcher, Marc Newlin(SkySafe), Koh M. Nakagawa@@tsunek0h, CVE-2023-38545, CVE-2023-38039, CVE-2023-38546, Yann GASCUEL(Alter Solutions), Anthony Cruz Tyrant Corp@@App, Wojciech Regula(SecuRing), Zhenjiang Zhao(Pangu Team), Qianxin, Junsung Lee, Meysam Firouzi@@R00tkitSMM, Pan ZhenPeng@@Peterpan0927(STAR Labs SG Pte), Eloi Benoist-Vanderbeken@@elvanderb(Synacktiv), CVE-2023-42893, CVE-2023-3618, CVE-2020-19185, CVE-2020-19186, CVE-2020-19187, CVE-2020-19188, CVE-2020-19189, CVE-2020-19190, Ron Masas(BreakPoint), Csaba Fitzl@@theevilbit(OffSec), Csaba Fitzl@@theevilbit(Offensive Security), Arsenii Kostromin (0x3c3e), Mattie Behrens, Joshua Jewett@@JoshJewett33, Zhongquan Li@@Guluisacat, Zhongquan Li@@Guluisacat(Dawn Security Lab of JingDong), CVE-2023-5344, Pwn2car, Zoom Offensive Security Team, Nan Wang@@eternalsakura13(360 Vulnerability Research Institute), rushikesh nandedkar, SungKwon Lee (Demon.Team), Apple
Affected Software
2 affected componentsFixes available
Apple macOS<14.2
14.2
macOS>=14.0<14.2
Event History
Dec 11, 2023
Data Sourced
via Apple·12:00 AM
DescriptionWeaknessAffected Software
Dec 12, 2023
CVE Published
via MITRE·12:27 AM
Data Sourced
via MITRE·12:27 AM
DescriptionWeakness
Data Sourced
via NVD·01:15 AM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2023-42874?
CVE-2023-42874 is classified as a security vulnerability that impacts accessibility features in macOS.
2
How do I fix CVE-2023-42874?
To fix CVE-2023-42874, update your system to macOS Sonoma version 14.2 or later.
3
What does CVE-2023-42874 affect?
CVE-2023-42874 affects secure text fields displayed via the Accessibility Keyboard in macOS.
4
Which versions of macOS are affected by CVE-2023-42874?
Versions of macOS from 14.0 up to but not including 14.2 are affected by CVE-2023-42874.
5
Can I use a physical keyboard with the Accessibility Keyboard after fixing CVE-2023-42874?
Yes, after applying the fix, using a physical keyboard with the Accessibility Keyboard will not expose secure text fields.