CVE-2023-42935: Medium severity apple macos vulnerability
An authentication issue was addressed with improved state management. This issue is fixed in macOS Ventura 13.6.4. A local attacker may be able to view the previous logged in user’s desktop from the fast user switching screen.
Other sources
LoginWindow. An authentication issue was addressed with improved state management.
— Apple
Credit
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2023-30774
- CVE-2023-40444
- CVE-2023-42952
- CVE-2023-42945
- CVE-2023-41072
- CVE-2023-42857
- CVE-2023-40449
- CVE-2023-42823
- CVE-2023-41989
- CVE-2023-42854
- CVE-2023-40413
- CVE-2023-42834
- CVE-2023-42844
- CVE-2023-42953
- CVE-2023-40416
- CVE-2023-42848
- CVE-2023-40423
- CVE-2023-38403
- CVE-2023-42849
- CVE-2023-42850
- CVE-2023-40446
- CVE-2023-42942
- CVE-2023-42861
- CVE-2023-42935
- CVE-2023-40408
- CVE-2023-40405
- CVE-2023-28826
- CVE-2023-42856
- CVE-2023-40404
- CVE-2023-42859
- CVE-2023-42877
- CVE-2023-42840
- CVE-2023-42853
- CVE-2023-42860
- CVE-2023-42889
- CVE-2023-42847
- CVE-2023-42845
- CVE-2023-42841
- CVE-2023-42873
- CVE-2023-42838
- CVE-2023-42835
- CVE-2023-41977
- CVE-2023-42438
- CVE-2023-42836
- CVE-2023-42839
- CVE-2023-42878
- CVE-2023-41982
- CVE-2023-41997
- CVE-2023-41988
- CVE-2023-42946
- CVE-2023-36191
- CVE-2023-40421
- CVE-2023-42842
- CVE-2023-4733
- CVE-2023-4734
- CVE-2023-4735
- CVE-2023-4736
- CVE-2023-4738
- CVE-2023-4750
- CVE-2023-4751
- CVE-2023-4752
- CVE-2023-4781
- CVE-2023-41254
- CVE-2023-40447
- CVE-2023-41976
- CVE-2023-42852
- CVE-2023-42843
- CVE-2023-41983
- CVE-2023-41975
- CVE-2023-42858
- CVE-2024-23212
- CVE-2023-42937
- CVE-2023-40528
- CVE-2023-38545
- CVE-2023-38039
- CVE-2023-38546
- CVE-2024-23224
- CVE-2023-42888
- CVE-2024-23207
- CVE-2023-42887
- CVE-2024-27791
- CVE-2024-23222
Frequently Asked Questions
What is the severity of CVE-2023-42935?
CVE-2023-42935 is considered a moderate severity vulnerability due to potential unauthorized access to user sessions.
How do I fix CVE-2023-42935?
To fix CVE-2023-42935, upgrade to macOS Ventura 13.6.4 or macOS Sonoma 14.1.
Who is affected by CVE-2023-42935?
Users of macOS versions prior to 13.6.4 and between 14.0 and 14.1 are affected by CVE-2023-42935.
What type of attack does CVE-2023-42935 involve?
CVE-2023-42935 involves a local attack allowing visibility of the previous user's desktop during fast user switching.
When was CVE-2023-42935 fixed?
CVE-2023-42935 was fixed in macOS Ventura 13.6.4 and macOS Sonoma 14.1.