CVE-2023-42886: Input Validation
Published Dec 11, 2023
·Updated
Accessibility. A privacy issue was addressed with improved private data redaction for log entries.
Credit
Koh M. Nakagawa@@tsunek0h, Mickey Jin@@patch1t, an anonymous researcher, Marc Newlin(SkySafe), CVE-2023-38545, CVE-2023-38039, CVE-2023-38546, Yann GASCUEL(Alter Solutions), Anthony Cruz Tyrant Corp@@App, Wojciech Regula(SecuRing), Zhenjiang Zhao(Pangu Team), Qianxin, Junsung Lee, Meysam Firouzi@@R00tkitSMM, Michael DePlante@@izobashi(Trend Micro Zero Day Initiative), Pan ZhenPeng@@Peterpan0927(STAR Labs SG Pte), Eloi Benoist-Vanderbeken@@elvanderb(Synacktiv), CVE-2023-42893, CVE-2023-3618, CVE-2020-19185, CVE-2020-19186, CVE-2020-19187, CVE-2020-19188, CVE-2020-19189, CVE-2020-19190, Ron Masas(BreakPoint), Csaba Fitzl@@theevilbit(OffSec), Csaba Fitzl@@theevilbit(Offensive Security), Arsenii Kostromin (0x3c3e), Mattie Behrens, Joshua Jewett@@JoshJewett33, Zhongquan Li@@Guluisacat, Zhongquan Li@@Guluisacat(Dawn Security Lab of JingDong), CVE-2023-5344, Pwn2car, Zoom Offensive Security Team, Nan Wang@@eternalsakura13(360 Vulnerability Research Institute), rushikesh nandedkar, SungKwon Lee (Demon.Team), Noah Roskin-Frazee, Pr, Ivan Fratric(Google Project Zero), (Trend Micro Zero Day Initiative), Don Clarke, Kirin@@Pwnrin, Jewel Lambert, Yiğit Can YILMAZ@@yilmazcanyigit(Offensive Security), (Offensive Security), Yiğit Can YILMAZ@@yilmazcanyigit, Zhipeng Huo@@R3dF09(Tencent Security Xuanwu Lab), Apple
Affected Software
6 affected componentsFixes available
Apple macOS<14.2
14.2
macOS<12.7.2
12.7.2
macOS Ventura<13.6.3
13.6.3
macOS>=12.0.0<12.7.2
macOS>=13.0<13.6.3
macOS>=14.0<14.2
Event History
Dec 11, 2023
Data Sourced
via Apple·12:00 AM
DescriptionWeaknessAffected Software
Updated
via Apple·12:00 AM
DescriptionWeakness
Updated
via Apple·12:00 AM
Affected Software
Updated
via Apple·12:00 AM
DescriptionWeaknessAffected Software
Updated
via Apple·12:00 AM
DescriptionAffected Software
Dec 12, 2023
CVE Published
via MITRE·12:27 AM
Data Sourced
via MITRE·12:27 AM
DescriptionWeakness
Data Sourced
via NVD·01:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2023-42886?
CVE-2023-42886 has been classified as a high-severity vulnerability affecting certain versions of macOS.
2
How do I fix CVE-2023-42886?
To fix CVE-2023-42886, update your macOS to versions 14.2, 13.6.3, or 12.7.2 as released by Apple.
3
What type of vulnerability is CVE-2023-42886?
CVE-2023-42886 is an out-of-bounds read vulnerability that may lead to unexpected app termination or arbitrary code execution.
4
Which versions of macOS are affected by CVE-2023-42886?
CVE-2023-42886 affects macOS versions prior to 14.2, 13.6.3, and 12.7.2.
5
What component of macOS is impacted by CVE-2023-42886?
CVE-2023-42886 impacts the CoreServices component of macOS.