CVE-2023-42977: Use After Free
A path handling issue was addressed with improved validation. This issue is fixed in iOS 17 and iPadOS 17, macOS Sonoma 14. An app may be able to break out of its sandbox.
Other sources
Accessibility. This issue was addressed with improved redaction of sensitive information.
— Apple
Airport. A permissions issue was addressed with improved redaction of sensitive information.
— Apple
AMD. A buffer overflow issue was addressed with improved memory handling.
— Apple
AMD. The issue was addressed with improved memory handling.
— Apple
App Store. The issue was addressed with improved handling of protocols.
— Apple
Credit
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2023-40529
- CVE-2023-40384
- CVE-2023-40448
- CVE-2023-42969
- CVE-2023-40432
- CVE-2023-41174
- CVE-2023-40409
- CVE-2023-40412
- CVE-2023-42871
- CVE-2023-41071
- CVE-2023-40399
- CVE-2023-40410
- CVE-2023-42872
- CVE-2023-42925
- CVE-2023-38612
- CVE-2023-32361
- CVE-2023-41232
- CVE-2023-35984
- CVE-2023-41065
- CVE-2023-38596
- CVE-2023-40420
- CVE-2023-40528
- CVE-2023-32396
- CVE-2023-41069
- CVE-2023-41980
- CVE-2023-40395
- CVE-2023-40431
- CVE-2023-40391
- CVE-2023-40441
- CVE-2023-40434
- CVE-2023-42961
- CVE-2023-40396
- CVE-2023-41995
- CVE-2023-42870
- CVE-2023-41974
- CVE-2023-41981
- CVE-2023-41984
- CVE-2023-40429
- CVE-2023-41060
- CVE-2023-40400
- CVE-2023-40454
- CVE-2023-41073
- CVE-2023-40403
- CVE-2023-40427
- CVE-2023-42957
- CVE-2023-41068
- CVE-2023-41986
- CVE-2023-40401
- CVE-2023-40393
- CVE-2023-42949
- CVE-2023-40456
- CVE-2023-40520
- CVE-2023-42934
- CVE-2023-42977
- CVE-2023-41063
- CVE-2023-40422
- CVE-2023-35990
- CVE-2023-40417
- CVE-2023-42973
- CVE-2023-40452
- CVE-2023-41070
- CVE-2023-40419
- CVE-2023-40428
- CVE-2023-41968
- CVE-2023-38614
- CVE-2023-40424
- CVE-2023-39434
- CVE-2023-40414
- CVE-2023-42970
- CVE-2023-41074
- CVE-2023-35074
- CVE-2023-42875
- CVE-2023-32359
- CVE-2023-40385
- CVE-2023-42833
- CVE-2023-38610
- CVE-2023-32377
- CVE-2023-38615
- CVE-2023-42929
- CVE-2023-40402
- CVE-2023-40426
- CVE-2023-42876
- CVE-2023-29497
- CVE-2023-42943
- CVE-2023-40406
- CVE-2023-40438
- CVE-2023-41994
- CVE-2023-40407
- CVE-2023-42933
- CVE-2023-40411
- CVE-2023-42959
- CVE-2023-23495
- CVE-2023-41077
- CVE-2023-38586
- CVE-2023-40436
- CVE-2023-41067
- CVE-2023-32421
- CVE-2023-42981
- CVE-2023-42982
- CVE-2023-42983
- CVE-2023-42826
- CVE-2023-42918
- CVE-2023-40455
- CVE-2023-40386
- CVE-2023-38408
- CVE-2023-37448
- CVE-2023-38607
- CVE-2023-41987
- CVE-2023-39233
- CVE-2023-40388
- CVE-2023-40425
- CVE-2023-40430
- CVE-2023-41996
- CVE-2023-41078
- CVE-2023-40541
- CVE-2023-41079
- CVE-2023-40443
- CVE-2023-40450
- CVE-2023-42948
- CVE-2023-41993
- CVE-2023-41076
- CVE-2023-41066
- CVE-2023-41979
Frequently Asked Questions
What is the severity of CVE-2023-42977?
CVE-2023-42977 is considered a high severity vulnerability due to its potential impact on sensitive information exposure.
How do I fix CVE-2023-42977?
To fix CVE-2023-42977, update your Apple iOS or iPadOS to version 17 to ensure you have the latest security enhancements.
What types of devices are affected by CVE-2023-42977?
CVE-2023-42977 affects Apple iOS and iPadOS devices running versions up to but not including 17.
What kind of issue is CVE-2023-42977?
CVE-2023-42977 involves accessibility and permissions issues that could allow sensitive information to be improperly handled.
Is CVE-2023-42977 related to Apple software only?
Yes, CVE-2023-42977 specifically affects Apple software, including iOS and iPadOS versions prior to 17.