CVE-2023-42970: Use After Free
A use-after-free issue was addressed with improved memory management. This issue is fixed in iOS 17 and iPadOS 17, macOS Sonoma 14, watchOS 10, tvOS 17, Safari 17. Processing web content may lead to arbitrary code execution.
Other sources
Accessibility. This issue was addressed with improved redaction of sensitive information.
— Apple
Airport. A permissions issue was addressed with improved redaction of sensitive information.
— Apple
AMD. A buffer overflow issue was addressed with improved memory handling.
— Apple
AMD. The issue was addressed with improved memory handling.
— Apple
App Store. The issue was addressed with improved handling of protocols.
— Apple
Credit
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2023-40417
- CVE-2023-40385
- CVE-2023-42833
- CVE-2023-39434
- CVE-2023-40414
- CVE-2023-42970
- CVE-2023-40451
- CVE-2023-41074
- CVE-2023-35074
- CVE-2023-42875
- CVE-2023-41993
- CVE-2023-40384
- CVE-2023-40448
- CVE-2023-40432
- CVE-2023-41174
- CVE-2023-40409
- CVE-2023-40412
- CVE-2023-41071
- CVE-2023-40399
- CVE-2023-40410
- CVE-2023-32361
- CVE-2023-35984
- CVE-2023-41065
- CVE-2023-38596
- CVE-2023-40420
- CVE-2023-40528
- CVE-2023-32396
- CVE-2023-40395
- CVE-2023-40391
- CVE-2023-40396
- CVE-2023-41981
- CVE-2023-41984
- CVE-2023-40429
- CVE-2023-40400
- CVE-2023-40454
- CVE-2023-41073
- CVE-2023-40403
- CVE-2023-40427
- CVE-2023-41068
- CVE-2023-42949
- CVE-2023-40456
- CVE-2023-40520
- CVE-2023-41063
- CVE-2023-40452
- CVE-2023-40419
- CVE-2023-41968
- CVE-2023-42957
- CVE-2023-40418
- CVE-2023-35990
- CVE-2023-41070
- CVE-2023-40424
- CVE-2023-40529
- CVE-2023-42969
- CVE-2023-42871
- CVE-2023-42872
- CVE-2023-42925
- CVE-2023-38612
- CVE-2023-41232
- CVE-2023-41069
- CVE-2023-41980
- CVE-2023-40431
- CVE-2023-40441
- CVE-2023-40434
- CVE-2023-42961
- CVE-2023-41995
- CVE-2023-42870
- CVE-2023-41974
- CVE-2023-41060
- CVE-2023-41986
- CVE-2023-40401
- CVE-2023-40393
- CVE-2023-42934
- CVE-2023-42977
- CVE-2023-40422
- CVE-2023-42973
- CVE-2023-40428
- CVE-2023-38614
- CVE-2023-32359
- CVE-2023-38610
- CVE-2023-32377
- CVE-2023-38615
- CVE-2023-42929
- CVE-2023-40402
- CVE-2023-40426
- CVE-2023-42876
- CVE-2023-29497
- CVE-2023-42943
- CVE-2023-40406
- CVE-2023-40438
- CVE-2023-41994
- CVE-2023-40407
- CVE-2023-42933
- CVE-2023-40411
- CVE-2023-42959
- CVE-2023-23495
- CVE-2023-41077
- CVE-2023-38586
- CVE-2023-40436
- CVE-2023-41067
- CVE-2023-32421
- CVE-2023-42981
- CVE-2023-42982
- CVE-2023-42983
- CVE-2023-42826
- CVE-2023-42918
- CVE-2023-40455
- CVE-2023-40386
- CVE-2023-38408
- CVE-2023-37448
- CVE-2023-38607
- CVE-2023-41987
- CVE-2023-39233
- CVE-2023-40388
- CVE-2023-40425
- CVE-2023-40430
- CVE-2023-41996
- CVE-2023-41078
- CVE-2023-40541
- CVE-2023-41079
- CVE-2023-40443
- CVE-2023-40450
- CVE-2023-42948
- CVE-2023-41076
- CVE-2023-41066
- CVE-2023-41979
Frequently Asked Questions
What is the severity of CVE-2023-42970?
CVE-2023-42970 has been assessed with a critical severity level due to its potential impact on sensitive information redaction.
How do I fix CVE-2023-42970?
To fix CVE-2023-42970, users should update their affected Apple devices to the latest version of iOS, iPadOS, watchOS, or tvOS as recommended by Apple.
What systems are affected by CVE-2023-42970?
CVE-2023-42970 affects several Apple systems including watchOS versions below 10 and iOS and iPadOS versions below 17.
What are the potential impacts of CVE-2023-42970?
The potential impacts of CVE-2023-42970 include unauthorized access to sensitive information due to a permissions issue on affected Apple devices.
Is there any known exploitation of CVE-2023-42970?
As of now, there are no reports of known exploitation for CVE-2023-42970 in the wild, but users are advised to update their software to mitigate risks.