CVE-2023-42928: High severity apple ios and ipados vulnerability
Automation. The issue was addressed with improved checks.
Other sources
Contacts. A privacy issue was addressed with improved private data redaction for log entries.
— Apple
Core Recents. The issue was resolved by sanitizing logging
— Apple
CoreAnimation. The issue was addressed with improved memory handling.
— Apple
FairPlay. The issue was addressed with improved bounds checks.
— Apple
The issue was addressed with improved bounds checks. This issue is fixed in iOS 17.1 and iPadOS 17.1. An app may be able to gain elevated privileges.
— MITRE
Credit
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2023-42952
- CVE-2023-41072
- CVE-2023-42857
- CVE-2023-40449
- CVE-2023-42823
- CVE-2023-42928
- CVE-2023-40413
- CVE-2023-42834
- CVE-2023-42953
- CVE-2023-40416
- CVE-2023-42848
- CVE-2023-40423
- CVE-2023-42849
- CVE-2023-40446
- CVE-2023-42942
- CVE-2023-40408
- CVE-2023-42846
- CVE-2023-42847
- CVE-2023-42845
- CVE-2023-42841
- CVE-2023-42873
- CVE-2023-42951
- CVE-2023-42836
- CVE-2023-42839
- CVE-2023-42855
- CVE-2023-42878
- CVE-2023-41982
- CVE-2023-41997
- CVE-2023-41988
- CVE-2023-42946
- CVE-2023-40445
- CVE-2023-41254
- CVE-2023-40447
- CVE-2023-41976
- CVE-2023-42852
- CVE-2023-42843
- CVE-2023-42939
- CVE-2023-41983
Frequently Asked Questions
What is the severity of CVE-2023-42928?
CVE-2023-42928 has been assessed as a critical vulnerability due to its potential to allow an app to gain elevated privileges.
How do I fix CVE-2023-42928?
To mitigate CVE-2023-42928, update your device to iOS 17.1 or iPadOS 17.1.
What devices are affected by CVE-2023-42928?
CVE-2023-42928 affects devices running iOS versions prior to 17.1 and iPadOS versions prior to 17.1.
Is CVE-2023-42928 still a risk if my device is updated?
No, updating to iOS 17.1 or iPadOS 17.1 resolves the risk associated with CVE-2023-42928.
What type of vulnerability is CVE-2023-42928?
CVE-2023-42928 is a privilege escalation vulnerability due to inadequate bounds checking.