CVE-2023-42969: Buffer Overflow
Published Sep 18, 2023
·Updated
Accessibility. This issue was addressed with improved redaction of sensitive information.
Credit
pattern-f@@pattern_F_(Ant Security Light), Mohamed GHANNAM@@_simo36, Ye Zhang@@VAR10CK(Baidu Security), Tim Michaud@@TimGMichaud(Moveworks), Chris Ross (Zoom), Liang Wei(PixiePoint Security), JeongOhKyea(Theori), 이준성(Junsung Lee)(Cross Republic), Mickey Jin@@patch1t, Pan ZhenPeng@@Peterpan0927(STAR Labs SG Pte), Linus Henze(Pinauten GmbH), Bill Marczak(The Citizen Lab at The University of Toronto's Munk School), Maddie Stone(Google's Threat Analysis Group), Zhipeng Huo@@R3dF09(Tencent Security Xuanwu Lab), Dohyun Lee@@l33d0hyun(PK Security), Adam M.(SecuRing), (SecuRing), Wojciech Regula(SecuRing), Certik Skyfall Team, Yiğit Can YILMAZ@@yilmazcanyigit, Kirin@@Pwnrin, James Hutchins, Wojciech Reguła@@_r3ggi, Csaba Fitzl@@theevilbit(Offensive Security), zer0k, Adam M., Noah Roskin-Frazee, Professor Jason Lau (ZeroClicks.ai Lab), Will Brattain at Trail(Bits), Kirin@@Pwnrin(NorthSea), Zhice Yang (ShanghaiTech University), Antonio Zekic@@antoniozekic(Dataflow Security), Ron Masas(Imperva), Mikko Kenttälä )@@Turmio_(SensorFu), Certik Skyfall Team(Ant Security Light), Zweig(Kunlun Lab), Félix Poulin-Bélanger, Michael (Biscuit) Thomas, 张师傅(@京东蓝军), Joseph Ravichandran@@0xjprx(MIT CSAIL), Sei K., Adam M.(BreakPoint Security Research), (BreakPoint Security Research), Ron Masas(BreakPoint Security Research), Gergely Kalman@@gergely_kalman, weize she, an anonymous researcher, Berke Kırbaş, Harsh Jaiswal, Tomi Tokics@@tomitokics(iTomsn0w), Adriatik Raci(Sentry Cybersecurity), Narendra Bhati (twitter.com/imnarendrabhati)(Suma Soft Pvt), Pune (India), Kenneth Chew, Arsenii Kostromin (0x3c3e), Abhay Kailasia@@abhay_kailasia(Lakshmi Narain College Of Technology Bhopal), Brian McNulty(Offensive Security), Arsenii Kostromin (0x3c3e)(Offensive Security), Joshua Jewett@@JoshJewett33(Offensive Security), (Offensive Security), Francisco Alonso@@revskills(PK Security), (PK Security), Francisco Alonso@@revskills, Jie Ding@@Lime(HKUS3 Lab), Dong Jun Kim@@smlijun(AbyssLab), Jong Seong Kim@@nevul37(AbyssLab), zhunki, 이준성(Junsung Lee), Claire Houston, Anonymous, Wang Yu(Cyberserval), w0wbox, ABC Research s.r.o., Koh M. Nakagawa@@tsunek0h, Yishu Wang, Cristian Dinca(Computer Science), Romania, Halle Winkler, Politepix@@hallewinkler, Noah Roskin-Frazee(Offensive Security), Pr(Offensive Security), Murray Mike, (Ant Security Light), Ferdous Saljooki@@malwarezoo(Jamf Software), Meng Zhang (鲸落)(NorthSea), Brian McNulty(Texts), (Texts), Kishan Bagaria(Texts), Michael DePlante@@izobashi(Trend Micro Zero Day Initiative), baba yaga, Serkan Erayabakan(George Mason University), David Kotval(George Mason University), Akincibor(George Mason University), Sina Ahmadi(George Mason University), Billy Tabrizi, Kirin@@Pwnrin(SecuRing), Luan Herrera@@lbherrera_, Noah Roskin-Frazee (ZeroClicks.ai Lab), James Duffy (mangoSecure), Ron Masas(BreakPoint), Thijs Alkemade@@xnyhps(Computest Sector 7), Andrew Haggard, (AbyssLab), An anonymous researcher(MacEnhance), Jeremy Legendre(MacEnhance), Felix Kratz
Affected Software
11 affected componentsFixes available
macOS Ventura<13.6
13.6
Apple iOS and iPadOS<17
17
Apple iOS, iPadOS, and macOS<17
17
macOS<12.7
12.7
Apple macOS<14
14
Apple iOS and iPadOS<16.7
16.7
Apple iOS, iPadOS, and macOS<16.7
16.7
Apple iOS, iPadOS, and macOS<16.7
iPhone OS<16.7
macOS<12.7
macOS>=13.0<13.6
Event History
Sep 18, 2023
Data Sourced
via Apple·12:00 AM
DescriptionWeaknessAffected Software
Updated
via Apple·12:00 AM
DescriptionWeakness
Sep 21, 2023
Updated
via Apple·12:00 AM
Affected Software
Updated
via Apple·12:00 AM
DescriptionWeaknessAffected Software
Sep 26, 2023
Updated
via Apple·12:00 AM
DescriptionWeaknessAffected Software
Updated
via Apple·12:00 AM
Affected Software
Apr 11, 2025
CVE Published
via MITRE·02:53 PM
Data Sourced
via MITRE·02:53 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2023-42969?
CVE-2023-42969 has been rated as a high-severity vulnerability due to its potential impact on sensitive information exposure.
2
How do I fix CVE-2023-42969?
To fix CVE-2023-42969, update affected software to macOS Ventura version 13.6 or iOS/iPadOS version 17.
3
What products are affected by CVE-2023-42969?
CVE-2023-42969 affects macOS Ventura versions up to 13.6 and iOS/iPadOS versions up to 17.
4
What type of issue does CVE-2023-42969 address?
CVE-2023-42969 addresses an accessibility issue related to the redaction of sensitive information.
5
Is there a specific update release for CVE-2023-42969?
Yes, the fixes for CVE-2023-42969 are included in the latest updates for macOS Ventura 13.6 and iOS/iPadOS 17.