CVE-2023-42962
Published Dec 11, 2023
·Updated
Accessibility. A privacy issue was addressed with improved private data redaction for log entries.
Credit
Aymane Chabat, Mickey Jin@@patch1t, an anonymous researcher, Marc Newlin(SkySafe), Christopher Reynolds, Wojciech Regula(SecuRing), Zhenjiang Zhao(Pangu Team), Qianxin, Junsung Lee, Meysam Firouzi@@R00tkitSMM, Michael DePlante@@izobashi(Trend Micro Zero Day Initiative), Pan ZhenPeng@@Peterpan0927(STAR Labs SG Pte), Eloi Benoist-Vanderbeken@@elvanderb(Synacktiv), CVE-2023-42893, ARJUN S D, Csaba Fitzl@@theevilbit(OffSec), Andrew Goldberg(The McCombs School of Business), The University(Texas at Austin), Zhongquan Li@@Guluisacat(Dawn Security Lab of JingDong), Csaba Fitzl@@theevilbit(Offensive Security), Joshua Jewett@@JoshJewett33, Pwn2car, Zoom Offensive Security Team, Nan Wang@@eternalsakura13(360 Vulnerability Research Institute), rushikesh nandedkar, SungKwon Lee (Demon.Team), Noah Roskin-Frazee, Pr, Kirin@@Pwnrin, Apple
Affected Software
8 affected componentsFixes available
Apple iOS<17.2
17.2
Apple iPadOS<17.2
17.2
Apple iOS<16.7.3
16.7.3
Apple iPadOS<16.7.3
16.7.3
Apple iPadOS<16.7.3
Apple iPadOS>=17.0<17.2
Apple iPhone OS<16.7.3
Apple iPhone OS>=17.0<17.2
Event History
Dec 11, 2023
Data Sourced
via Apple·12:00 AM
DescriptionWeaknessAffected Software
Updated
via Apple·12:00 AM
DescriptionWeakness
Mar 28, 2024
CVE Published
via MITRE·03:39 PM
Data Sourced
via MITRE·03:39 PM
DescriptionWeakness
Data Sourced
via NVD·04:15 PM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2023-42962?
CVE-2023-42962 has been classified as a denial-of-service vulnerability affecting CallKit.
2
How do I fix CVE-2023-42962?
To fix CVE-2023-42962, update your Apple devices to iOS 17.2 or iPadOS 17.2, or the applicable previous versions 16.7.3.
3
Which Apple products are affected by CVE-2023-42962?
CVE-2023-42962 affects Apple iOS and iPadOS versions prior to 17.2 and 16.7.3.
4
Can CVE-2023-42962 be exploited remotely?
Yes, CVE-2023-42962 can potentially be exploited by remote attackers to cause a denial-of-service.
5
What versions have the vulnerability CVE-2023-42962 been patched in?
CVE-2023-42962 has been patched in iOS 17.2, iPadOS 17.2, iOS 16.7.3, and iPadOS 16.7.3.