CVE-2023-42894
Published Dec 11, 2023
·Updated
Accessibility. A privacy issue was addressed with improved private data redaction for log entries.
Credit
Noah Roskin-Frazee, Pr, Ivan Fratric(Google Project Zero), (Trend Micro Zero Day Initiative), Michael DePlante@@izobashi(Trend Micro Zero Day Initiative), Mickey Jin@@patch1t, an anonymous researcher, Marc Newlin(SkySafe), Koh M. Nakagawa@@tsunek0h, CVE-2023-38545, CVE-2023-38039, CVE-2023-38546, Yann GASCUEL(Alter Solutions), Anthony Cruz Tyrant Corp@@App, Wojciech Regula(SecuRing), Zhenjiang Zhao(Pangu Team), Qianxin, Junsung Lee, Meysam Firouzi@@R00tkitSMM, Pan ZhenPeng@@Peterpan0927(STAR Labs SG Pte), Eloi Benoist-Vanderbeken@@elvanderb(Synacktiv), CVE-2023-42893, CVE-2023-3618, CVE-2020-19185, CVE-2020-19186, CVE-2020-19187, CVE-2020-19188, CVE-2020-19189, CVE-2020-19190, Ron Masas(BreakPoint), Csaba Fitzl@@theevilbit(OffSec), Csaba Fitzl@@theevilbit(Offensive Security), Arsenii Kostromin (0x3c3e), Mattie Behrens, Joshua Jewett@@JoshJewett33, Zhongquan Li@@Guluisacat, Zhongquan Li@@Guluisacat(Dawn Security Lab of JingDong), CVE-2023-5344, Pwn2car, Zoom Offensive Security Team, Nan Wang@@eternalsakura13(360 Vulnerability Research Institute), rushikesh nandedkar, SungKwon Lee (Demon.Team), Don Clarke, Kirin@@Pwnrin, Jewel Lambert, Yiğit Can YILMAZ@@yilmazcanyigit(Offensive Security), (Offensive Security), Yiğit Can YILMAZ@@yilmazcanyigit, Zhipeng Huo@@R3dF09(Tencent Security Xuanwu Lab), Apple
Affected Software
6 affected componentsFixes available
Apple macOS<14.2
14.2
macOS<12.7.2
12.7.2
macOS Ventura<13.6.3
13.6.3
macOS>=12.0.0<12.7.2
macOS>=13.0<13.6.3
macOS>=14.0<14.2
Event History
Dec 11, 2023
Data Sourced
via Apple·12:00 AM
DescriptionWeaknessAffected Software
Updated
via Apple·12:00 AM
DescriptionWeakness
Updated
via Apple·12:00 AM
Affected Software
Updated
via Apple·12:00 AM
DescriptionWeaknessAffected Software
Updated
via Apple·12:00 AM
DescriptionAffected Software
Dec 12, 2023
CVE Published
via MITRE·12:27 AM
Data Sourced
via MITRE·12:27 AM
DescriptionWeakness
Data Sourced
via NVD·01:15 AM
DescriptionSeverityAffected Software
Feb 8, 2024
News Published
via The Register·02:00 PM
News Published
via The Register·02:05 PM
Frequently Asked Questions
1
What is the severity of CVE-2023-42894?
The severity of CVE-2023-42894 is high due to the potential unauthorized access to sensitive information.
2
How do I fix CVE-2023-42894?
To fix CVE-2023-42894, update to macOS Sonoma 14.2, macOS Ventura 13.6.3, or macOS Monterey 12.7.2.
3
What does CVE-2023-42894 affect?
CVE-2023-42894 affects multiple versions of macOS, including Monterey, Ventura, and Sonoma.
4
Can CVE-2023-42894 be exploited remotely?
CVE-2023-42894 may allow local applications to access sensitive information, indicating a potential for exploitation.
5
Is CVE-2023-42894 related to AppleEvents?
Yes, CVE-2023-42894 is associated with AppleEvents and involves sensitive information redaction issues.