CVE-2023-42891: Input Validation
Accessibility. A privacy issue was addressed with improved private data redaction for log entries.
Other sources
Accessibility. This issue was addressed with improved state management.
— Apple
Accounts. A privacy issue was addressed with improved private data redaction for log entries.
— Apple
An authentication issue was addressed with improved state management. This issue is fixed in macOS Sonoma 14.2, macOS Ventura 13.6.3, macOS Monterey 12.7.2. An app may be able to monitor keystrokes without user permission.
— MITRE
AppleEvents. This issue was addressed with improved redaction of sensitive information.
— Apple
AppleGraphicsControl. Multiple memory corruption issues were addressed with improved input validation.
— Apple
Credit
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2023-42874
- CVE-2023-42937
- CVE-2023-42919
- CVE-2023-42894
- CVE-2023-42901
- CVE-2023-42902
- CVE-2023-42912
- CVE-2023-42903
- CVE-2023-42904
- CVE-2023-42905
- CVE-2023-42906
- CVE-2023-42907
- CVE-2023-42908
- CVE-2023-42909
- CVE-2023-42910
- CVE-2023-42911
- CVE-2023-42926
- CVE-2023-42882
- CVE-2023-42881
- CVE-2023-42924
- CVE-2023-42896
- CVE-2023-42884
- CVE-2023-45866
- CVE-2023-42900
- CVE-2023-42886
- CVE-2023-38545
- CVE-2023-38039
- CVE-2023-38546
- CVE-2023-42931
- CVE-2023-42892
- CVE-2023-42922
- CVE-2023-42898
- CVE-2023-42899
- CVE-2023-42888
- CVE-2023-42891
- CVE-2023-42974
- CVE-2023-42914
- CVE-2023-42893
- CVE-2023-3618
- CVE-2020-19185
- CVE-2020-19186
- CVE-2020-19187
- CVE-2020-19188
- CVE-2020-19189
- CVE-2020-19190
- CVE-2023-42887
- CVE-2023-42936
- CVE-2023-40390
- CVE-2023-42842
- CVE-2023-42930
- CVE-2023-42913
- CVE-2023-42932
- CVE-2023-42947
- CVE-2023-40389
- CVE-2023-5344
- CVE-2023-42890
- CVE-2023-42883
- CVE-2023-42950
- CVE-2023-42956
- CVE-2023-41989
- CVE-2023-42834
- CVE-2023-42838
- CVE-2023-42836
- CVE-2023-42952
- CVE-2023-43010
Frequently Asked Questions
What is the severity of CVE-2023-42891?
CVE-2023-42891 is classified with a significant severity as it involves an authentication issue that may allow an app to monitor keystrokes without user consent.
How do I fix CVE-2023-42891?
To mitigate CVE-2023-42891, users should upgrade to macOS Sonoma 14.2, macOS Ventura 13.6.3, or macOS Monterey 12.7.2.
Which macOS versions are affected by CVE-2023-42891?
CVE-2023-42891 affects macOS versions from 12.0.0 up to 12.7.2, as well as versions from 13.0 to 13.6.3, and from 14.0 to 14.2.
What kind of issue does CVE-2023-42891 address?
CVE-2023-42891 addresses an authentication issue with improved state management to prevent unauthorized keystroke monitoring.
What is the impact of CVE-2023-42891?
The impact of CVE-2023-42891 allows potentially malicious applications to monitor user keystrokes without their permission.