CVE-2023-42962: High severity Apple iOS vulnerability
Accessibility. A privacy issue was addressed with improved private data redaction for log entries.
Other sources
Accounts. A privacy issue was addressed with improved private data redaction for log entries.
— Apple
Assets. An issue was addressed with improved handling of temporary files.
— Apple
AVEVideoEncoder. This issue was addressed with improved redaction of sensitive information.
— Apple
Bluetooth. The issue was addressed with improved checks.
— Apple
CallKit. This issue was addressed with improved checks
— Apple
Credit
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2023-42919
- CVE-2023-42896
- CVE-2023-42884
- CVE-2023-42962
- CVE-2023-42922
- CVE-2023-42899
- CVE-2023-42974
- CVE-2023-42914
- CVE-2023-42893
- CVE-2023-42883
- CVE-2023-42917
- CVE-2023-42916
- CVE-2023-42937
- CVE-2023-45866
- CVE-2023-42941
- CVE-2023-42898
- CVE-2023-42888
- CVE-2023-42923
- CVE-2023-42936
- CVE-2023-42897
- CVE-2023-42947
- CVE-2023-40389
- CVE-2023-42890
- CVE-2023-42950
- CVE-2023-42956
- CVE-2023-43010
Frequently Asked Questions
What is the severity of CVE-2023-42962?
CVE-2023-42962 has been classified as a denial-of-service vulnerability affecting CallKit.
How do I fix CVE-2023-42962?
To fix CVE-2023-42962, update your Apple devices to iOS 17.2 or iPadOS 17.2, or the applicable previous versions 16.7.3.
Which Apple products are affected by CVE-2023-42962?
CVE-2023-42962 affects Apple iOS and iPadOS versions prior to 17.2 and 16.7.3.
Can CVE-2023-42962 be exploited remotely?
Yes, CVE-2023-42962 can potentially be exploited by remote attackers to cause a denial-of-service.
What versions have the vulnerability CVE-2023-42962 been patched in?
CVE-2023-42962 has been patched in iOS 17.2, iPadOS 17.2, iOS 16.7.3, and iPadOS 16.7.3.