Apple Security Advisories · September 2023 — Apple Security Advisories
135 advisories 135 CVEs 6 EXPLOITED

Apple-vendor CVEs for 2023-09. Mirrored into Vulnetix VDB.

Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity). 6 are already weaponised in the wild — see the Exploited section.

What would you fix first?

The advisories below are ordered by the Vulnetix risk prioritization strategy: exploitation evidence first, scores second. On the interactive page you can switch to three other lenses.

Advisories

CVE-2023-5217

OtherExploitedCISA KEV listedCRITICAL2023-09-27

Heap buffer overflow in vp8 encoding in libvpx in Google Chrome prior to 117.0.5938.132 and libvpx 1.13.1 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2023-5217

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
Upstream advisory

CVE-2023-41064

iPadOSExploitedCISA KEV listedCRITICAL2023-09-07

A buffer overflow issue was addressed with improved memory handling. This issue is fixed in iOS 16.6.1 and iPadOS 16.6.1, macOS Monterey 12.6.9, macOS Ventura 13.5.2, iOS 15.7.9 and iPadOS 15.7.9, macOS Big Sur 11.7.10. Processing a maliciously crafted...

CVEs:CVE-2023-41064

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
Upstream advisory

CVE-2023-41991

iPadOSExploitedCISA KEV listedMEDIUM2023-09-21

A certificate validation issue was addressed. This issue is fixed in macOS Ventura 13.6, iOS 16.7 and iPadOS 16.7. A malicious app may be able to bypass signature validation. Apple is aware of a report that this issue may have been actively exploited a...

CVEs:CVE-2023-41991

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
Upstream advisory

CVE-2023-41061

iPadOSExploitedCISA KEV listedCRITICAL2023-09-07

A validation issue was addressed with improved logic. This issue is fixed in watchOS 9.6.2, iOS 16.6.1 and iPadOS 16.6.1. A maliciously crafted attachment may result in arbitrary code execution. Apple is aware of a report that this issue may have been ...

CVEs:CVE-2023-41061

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
watchos affected apple
Upstream advisory

CVE-2023-41992

iPadOSExploitedCISA KEV listedHIGH2023-09-21

The issue was addressed with improved checks. This issue is fixed in macOS Monterey 12.7, iOS 16.7 and iPadOS 16.7, macOS Ventura 13.6. A local attacker may be able to elevate their privileges. Apple is aware of a report that this issue may have been a...

CVEs:CVE-2023-41992

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
Upstream advisory

CVE-2023-41974

iPadOSExploitedCISA KEV listedCRITICAL2023-09-26

A use-after-free issue was addressed with improved memory management. This issue is fixed in iOS 17 and iPadOS 17, iOS 15.8.7 and iPadOS 15.8.7. An app may be able to execute arbitrary code with kernel privileges.

CVEs:CVE-2023-41974

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
Upstream advisory

CVE-2023-41060

iPadOSActive exploitation (sightings)CRITICAL2023-09-26

A type confusion issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14, iOS 17 and iPadOS 17. A remote user may be able to cause kernel code execution.

CVEs:CVE-2023-41060

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
Upstream advisory

CVE-2023-40385

iPadOSActive exploitation (sightings)MEDIUM2023-09-26

This issue was addressed by removing the vulnerable code. This issue is fixed in macOS Sonoma 14, Safari 17, iOS 17 and iPadOS 17. A remote attacker may be able to view leaked DNS queries with Private Relay turned on.

CVEs:CVE-2023-40385

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
safari affected apple
Upstream advisory

CVE-2023-40393

iPadOSActive exploitation (sightings)HIGH2023-09-26

An authentication issue was addressed with improved state management. This issue is fixed in iOS 17 and iPadOS 17, macOS Sonoma 14. Photos in the Hidden Photos Album may be viewed without authentication.

CVEs:CVE-2023-40393

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2023-29166

OtherActive exploitation (sightings)HIGH2023-09-06

A logic issue was addressed with improved state management. This issue is fixed in Pro Video Formats 2.2.5. A user may be able to elevate privileges.

CVEs:CVE-2023-29166

Affected products

ProductStatusVendorPackageEcosystem
pro_video_formats affected apple
Upstream advisory

CVE-2023-42961

iPadOSActive exploitation (sightings)MEDIUM2023-09-26

A path handling issue was addressed with improved validation. This issue is fixed in iOS 17 and iPadOS 17, iOS 16.7 and iPadOS 16.7, macOS Sonoma 14, macOS Ventura 13.6, macOS Monterey 12.7. A sandboxed process may be able to circumvent sandbox restric...

CVEs:CVE-2023-42961

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
Upstream advisory

CVE-2023-42981

macOSActive exploitation (sightings)HIGH2023-09-26

Processing a file may lead to a denial-of-service or potentially disclose memory contents. This issue is fixed in macOS 14. The issue was addressed with improved checks.

CVEs:CVE-2023-42981

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2023-41076

macOSActive exploitation (sightings)HIGH2023-09-26

An app may be able to elevate privileges. This issue is fixed in macOS 14. This issue was addressed by removing the vulnerable code.

CVEs:CVE-2023-41076

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2023-38614

iPadOSActive exploitation (sightings)MEDIUM2023-09-26

A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 17 and iPadOS 17, macOS Sonoma 14. An app may be able to access sensitive user data.

CVEs:CVE-2023-38614

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
Upstream advisory

CVE-2023-42982

macOSActive exploitation (sightings)HIGH2023-09-26

Processing a file may lead to a denial-of-service or potentially disclose memory contents. This issue is fixed in macOS 14. The issue was addressed with improved checks.

CVEs:CVE-2023-42982

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2023-42983

macOSActive exploitation (sightings)HIGH2023-09-26

Processing a file may lead to a denial-of-service or potentially disclose memory contents. This issue is fixed in macOS 14. The issue was addressed with improved checks.

CVEs:CVE-2023-42983

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2023-40396

iPadOSActive exploitation (sightings)CRITICAL2023-09-26

The issue was addressed with improved memory handling. This issue is fixed in iOS 17 and iPadOS 17, macOS Sonoma 14, watchOS 10, tvOS 17. An app may be able to execute arbitrary code with kernel privileges.

CVEs:CVE-2023-40396

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
tvos affected apple
watchos affected apple
Upstream advisory

CVE-2023-40529

iPadOSActive exploitation (sightings)MEDIUM2023-09-26

This issue was addressed with improved redaction of sensitive information. This issue is fixed in iOS 17 and iPadOS 17. A person with physical access to a device may be able to use VoiceOver to access private calendar information.

CVEs:CVE-2023-40529

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
Upstream advisory

CVE-2023-42871

iPadOSActive exploitation (sightings)CRITICAL2023-09-26

The issue was addressed with improved memory handling. This issue is fixed in macOS Sonoma 14, iOS 17 and iPadOS 17. An app may be able to execute arbitrary code with kernel privileges.

CVEs:CVE-2023-42871

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
Upstream advisory

CVE-2023-38612

iPadOSActive exploitation (sightings)LOW2023-09-26

The issue was addressed with improved checks. This issue is fixed in macOS Monterey 12.7, iOS 16.7 and iPadOS 16.7, iOS 17 and iPadOS 17, macOS Sonoma 14, macOS Ventura 13.6. An app may be able to access protected user data.

CVEs:CVE-2023-38612

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
Upstream advisory

CVE-2023-40430

macOSActive exploitation (sightings)MEDIUM2023-09-26

A logic issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14. An app may be able to access removable volumes without user consent.

CVEs:CVE-2023-40430

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2023-41994

macOSActive exploitation (sightings)MEDIUM2023-09-26

A logic issue was addressed with improved checks This issue is fixed in macOS Sonoma 14. A camera extension may be able to access the camera view from apps other than the app for which it was granted permission.

CVEs:CVE-2023-41994

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2023-38610

iPadOSActive exploitation (sightings)CRITICAL2023-09-26

A memory corruption issue was addressed by removing the vulnerable code. This issue is fixed in macOS Sonoma 14, iOS 17 and iPadOS 17. An app may be able to cause unexpected system termination or write kernel memory.

CVEs:CVE-2023-38610

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
Upstream advisory

CVE-2023-42870

iPadOSActive exploitation (sightings)CRITICAL2023-09-26

A use-after-free issue was addressed with improved memory management. This issue is fixed in macOS Sonoma 14, iOS 17 and iPadOS 17. An app may be able to execute arbitrary code with kernel privileges.

CVEs:CVE-2023-42870

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
Upstream advisory

CVE-2023-42933

macOSActive exploitation (sightings)HIGH2023-09-26

This issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14. An app may be able to gain elevated privileges.

CVEs:CVE-2023-42933

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2023-42977

iPadOSActive exploitation (sightings)HIGH2023-09-26

A path handling issue was addressed with improved validation. This issue is fixed in iOS 17 and iPadOS 17, macOS Sonoma 14. An app may be able to break out of its sandbox.

CVEs:CVE-2023-42977

Affected products

ProductStatusVendorPackageEcosystem
ipad_os affected apple
iphone_os affected apple
macos affected apple
Upstream advisory

CVE-2023-42934

iPadOSActive exploitation (sightings)HIGH2023-09-26

An information disclosure issue was addressed by removing the vulnerable code. This issue is fixed in macOS Sonoma 14, iOS 17 and iPadOS 17. An app with root privileges may be able to access private information.

CVEs:CVE-2023-42934

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
Upstream advisory

CVE-2023-40438

iPadOSActive exploitation (sightings)MEDIUM2023-09-26

An issue was addressed with improved handling of temporary files. This issue is fixed in macOS Sonoma 14, iOS 16.7 and iPadOS 16.7. An app may be able to access edited photos saved to a temporary directory.

CVEs:CVE-2023-40438

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
Upstream advisory

CVE-2023-42872

iPadOSActive exploitation (sightings)MEDIUM2023-09-26

The issue was addressed with additional permissions checks. This issue is fixed in macOS Sonoma 14, iOS 17 and iPadOS 17. An app may be able to access sensitive user data.

CVEs:CVE-2023-42872

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
safari affected apple
Upstream advisory

CVE-2023-42929

macOSActive exploitation (sightings)MEDIUM2023-09-26

The issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14. An app may be able to access protected user data.

CVEs:CVE-2023-42929

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2023-40411

macOSActive exploitation (sightings)HIGH2023-09-26

This issue was addressed with improved data protection. This issue is fixed in macOS Sonoma 14. An app may be able to access user-sensitive data.

CVEs:CVE-2023-40411

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2023-41987

macOSActive exploitation (sightings)MEDIUM2023-09-26

This issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14. An app may be able to access sensitive user data.

CVEs:CVE-2023-41987

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2023-42876

macOSActive exploitation (sightings)HIGH2023-09-26

The issue was addressed with improved bounds checks. This issue is fixed in macOS Sonoma 14. Processing a file may lead to a denial-of-service or potentially disclose memory contents.

CVEs:CVE-2023-42876

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2023-38607

macOSActive exploitation (sightings)MEDIUM2023-09-26

The issue was addressed with improved handling of caches. This issue is fixed in macOS Sonoma 14. An app may be able to modify Printer settings.

CVEs:CVE-2023-38607

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2023-42973

iPadOSActive exploitation (sightings)MEDIUM2023-09-26

Private Browsing tabs may be accessed without authentication. This issue is fixed in iOS 17 and iPadOS 17. The issue was addressed with improved UI.

CVEs:CVE-2023-42973

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
Upstream advisory

CVE-2023-42943

macOSActive exploitation (sightings)MEDIUM2023-09-26

A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in macOS Sonoma 14. An app may be able to read sensitive location information.

CVEs:CVE-2023-42943

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2023-42949

iPadOSActive exploitation (sightings)LOW2023-09-26

This issue was addressed with improved data protection. This issue is fixed in iOS 17 and iPadOS 17, macOS Sonoma 14, watchOS 10, tvOS 17. An app may be able to access edited photos saved to a temporary directory.

CVEs:CVE-2023-42949

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
tvos affected apple
watchos affected apple
Upstream advisory

CVE-2023-41069

iPadOSActive exploitation (sightings)MEDIUM2023-09-26

This issue was addressed by improving Face ID anti-spoofing models. This issue is fixed in iOS 17 and iPadOS 17. A 3D model constructed to look like the enrolled user may authenticate via Face ID.

CVEs:CVE-2023-41069

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
Upstream advisory

CVE-2023-42948

macOSActive exploitation (sightings)LOW2023-09-26

This issue was addressed through improved state management. This issue is fixed in macOS Sonoma 14. A Wi-Fi password may not be deleted when activating a Mac in macOS Recovery.

CVEs:CVE-2023-42948

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2023-42925

iPadOSActive exploitation (sightings)LOW2023-09-26

The issue was addressed with improved restriction of data container access. This issue is fixed in iOS 17 and iPadOS 17, macOS Sonoma 14. An app may be able to access Notes attachments.

CVEs:CVE-2023-42925

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
Upstream advisory

CVE-2023-42957

iPadOSActive exploitation (sightings)LOW2023-09-26

A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 17 and iPadOS 17, macOS Sonoma 14, watchOS 10. An app may be able to read sensitive location information.

CVEs:CVE-2023-42957

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
watchos affected apple
Upstream advisory

CVE-2023-42969

iPadOSActive exploitation (sightings)LOW2023-09-26

An app may be able to break out of its sandbox. This issue is fixed in iOS 17 and iPadOS 17, iOS 16.7 and iPadOS 16.7, macOS Sonoma 14, macOS Ventura 13.6, macOS Monterey 12.7. The issue was addressed with improved handling of caches.

CVEs:CVE-2023-42969

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
Upstream advisory

CVE-2023-42918

macOSActive exploitation (sightings)HIGH2023-09-26

A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sonoma 14. A sandboxed process may be able to circumvent sandbox restrictions.

CVEs:CVE-2023-42918

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2023-42959

macOSActive exploitation (sightings)CRITICAL2023-09-26

A race condition was addressed with improved state handling. This issue is fixed in macOS Sonoma 14. An app may be able to execute arbitrary code with kernel privileges.

CVEs:CVE-2023-42959

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2023-40400

iPadOSPoC exploitCRITICAL2023-09-26

This issue was addressed with improved checks. This issue is fixed in tvOS 17, iOS 17 and iPadOS 17, watchOS 10, macOS Sonoma 14. A remote user may cause an unexpected app termination or arbitrary code execution.

CVEs:CVE-2023-40400

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
tvos affected apple
watchos affected apple
Upstream advisory

CVE-2023-40448

iPadOSPoC exploitHIGH2023-09-26

The issue was addressed with improved handling of protocols. This issue is fixed in tvOS 17, iOS 16.7 and iPadOS 16.7, watchOS 10, iOS 17 and iPadOS 17, macOS Sonoma 14. A remote attacker may be able to break out of Web Content sandbox.

CVEs:CVE-2023-40448

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
tvos affected apple
watchos affected apple
Upstream advisory

CVE-2023-39434

iPadOSPoC exploitCRITICAL2023-09-26

A use-after-free issue was addressed with improved memory management. This issue is fixed in iOS 17 and iPadOS 17, watchOS 10, macOS Sonoma 14. Processing web content may lead to arbitrary code execution.

CVEs:CVE-2023-39434

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
watchos affected apple
Upstream advisory

CVE-2023-40407

macOSPoC exploitHIGH2023-09-26

The issue was addressed with improved bounds checks. This issue is fixed in macOS Sonoma 14. A remote attacker may be able to cause a denial-of-service.

CVEs:CVE-2023-40407

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2023-40420

iPadOSPoC exploitHIGH2023-09-26

The issue was addressed with improved memory handling. This issue is fixed in macOS Ventura 13.6, tvOS 17, iOS 16.7 and iPadOS 16.7, macOS Monterey 12.7, watchOS 10, iOS 17 and iPadOS 17, macOS Sonoma 14. Processing web content may lead to a denial-of-...

CVEs:CVE-2023-40420

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
tvos affected apple
watchos affected apple
Upstream advisory

CVE-2023-40403

iPadOSPoC exploitHIGH2023-09-26

The issue was addressed with improved memory handling. This issue is fixed in macOS Ventura 13.6, tvOS 17, iOS 16.7 and iPadOS 16.7, macOS Monterey 12.7, watchOS 10, iOS 17 and iPadOS 17, macOS Sonoma 14. Processing web content may disclose sensitive i...

CVEs:CVE-2023-40403

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
tvos affected apple
watchos affected apple
Upstream advisory

CVE-2023-38586

macOSPoC exploitCRITICAL2023-09-26

An access issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Sonoma 14. A sandboxed process may be able to circumvent sandbox restrictions.

CVEs:CVE-2023-38586

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2023-40455

macOSPoC exploitCRITICAL2023-09-26

A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sonoma 14. A sandboxed process may be able to circumvent sandbox restrictions.

CVEs:CVE-2023-40455

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2023-40414

iPadOSPoC exploitCRITICAL2023-09-26

A use-after-free issue was addressed with improved memory management. This issue is fixed in watchOS 10, iOS 17 and iPadOS 17, tvOS 17, macOS Sonoma 14, Safari 17. Processing web content may lead to arbitrary code execution.

CVEs:CVE-2023-40414

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
safari affected apple
tvos affected apple
watchos affected apple
Upstream advisory

CVE-2023-40436

macOSPoC exploitCRITICAL2023-09-26

The issue was addressed with improved bounds checks. This issue is fixed in macOS Sonoma 14. An attacker may be able to cause unexpected system termination or read kernel memory.

CVEs:CVE-2023-40436

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2023-40451

SafariPoC exploitCRITICAL2023-09-26

This issue was addressed with improved iframe sandbox enforcement. This issue is fixed in Safari 17. An attacker with JavaScript execution may be able to execute arbitrary code.

CVEs:CVE-2023-40451

Affected products

ProductStatusVendorPackageEcosystem
safari affected apple
Upstream advisory

CVE-2023-42833

iPadOSPoC exploitCRITICAL2023-09-26

A correctness issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14, Safari 17, iOS 17 and iPadOS 17. Processing web content may lead to arbitrary code execution.

CVEs:CVE-2023-42833

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
safari affected apple
Upstream advisory

CVE-2023-40441

iPadOSPoC exploitCRITICAL2023-09-26

A resource exhaustion issue was addressed with improved input validation. This issue is fixed in iOS 17 and iPadOS 17, macOS Sonoma 14. Processing web content may lead to a denial-of-service.

CVEs:CVE-2023-40441

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
Upstream advisory

CVE-2023-40417

iPadOSPoC exploitMEDIUM2023-09-26

A window management issue was addressed with improved state management. This issue is fixed in Safari 17, iOS 17 and iPadOS 17, watchOS 10, macOS Sonoma 14. Visiting a website that frames malicious content may lead to UI spoofing.

CVEs:CVE-2023-40417

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
safari affected apple
watchos affected apple
Upstream advisory

CVE-2023-39233

macOSPoC exploitHIGH2023-09-26

The issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14. Processing web content may disclose sensitive information.

CVEs:CVE-2023-39233

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2023-35984

iPadOSPoC exploitCRITICAL2023-09-26

The issue was addressed with improved checks. This issue is fixed in tvOS 17, iOS 17 and iPadOS 17, watchOS 10, macOS Sonoma 14. An attacker in physical proximity can cause a limited out of bounds write.

CVEs:CVE-2023-35984

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
tvos affected apple
watchos affected apple
Upstream advisory

CVE-2023-40388

macOSPoC exploitMEDIUM2023-09-26

A privacy issue was addressed with improved handling of temporary files. This issue is fixed in macOS Sonoma 14. Safari may save photos to an unprotected location.

CVEs:CVE-2023-40388

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2023-4781

OtherPoC exploitCRITICAL2023-09-05

Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.1873.

CVEs:CVE-2023-4781

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2023-4738

OtherPoC exploitCRITICAL2023-09-02

Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.1848.

CVEs:CVE-2023-4738

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2023-4751

OtherPoC exploitCRITICAL2023-09-03

Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.1331.

CVEs:CVE-2023-4751

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2023-4735

OtherPoC exploitCRITICAL2023-09-02

Out-of-bounds Write in GitHub repository vim/vim prior to 9.0.1847.

CVEs:CVE-2023-4735

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2023-4734

OtherPoC exploitCRITICAL2023-09-02

Integer Overflow or Wraparound in GitHub repository vim/vim prior to 9.0.1846.

CVEs:CVE-2023-4734

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2023-4752

OtherPoC exploitCRITICAL2023-09-04

Use After Free in GitHub repository vim/vim prior to 9.0.1858.

CVEs:CVE-2023-4752

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2023-40429

iPadOSPoC exploitMEDIUM2023-09-26

A permissions issue was addressed with improved validation. This issue is fixed in tvOS 17, iOS 17 and iPadOS 17, watchOS 10, macOS Sonoma 14. An app may be able to access sensitive user data.

CVEs:CVE-2023-40429

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
tvos affected apple
watchos affected apple
Upstream advisory

CVE-2023-4733

OtherPoC exploitCRITICAL2023-09-04

Use After Free in GitHub repository vim/vim prior to 9.0.1840.

CVEs:CVE-2023-4733

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2023-4750

OtherPoC exploitCRITICAL2023-09-04

Use After Free in GitHub repository vim/vim prior to 9.0.1857.

CVEs:CVE-2023-4750

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2023-42970

iPadOSPoC exploitCRITICAL2023-09-26

A use-after-free issue was addressed with improved memory management. This issue is fixed in iOS 17 and iPadOS 17, macOS Sonoma 14, watchOS 10, tvOS 17, Safari 17. Processing web content may lead to arbitrary code execution.

CVEs:CVE-2023-42970

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
safari affected apple
tvos affected apple
watchos affected apple
Upstream advisory

CVE-2023-41984

iPadOSPoC exploitCRITICAL2023-09-26

The issue was addressed with improved memory handling. This issue is fixed in macOS Ventura 13.6, tvOS 17, iOS 16.7 and iPadOS 16.7, macOS Monterey 12.7, watchOS 10, iOS 17 and iPadOS 17, macOS Sonoma 14. An app may be able to execute arbitrary code wi...

CVEs:CVE-2023-41984

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
tvos affected apple
watchos affected apple
Upstream advisory

CVE-2023-42875

iPadOSPoC exploitCRITICAL2023-09-26

Processing web content may lead to arbitrary code execution. This issue is fixed in iOS 17 and iPadOS 17, macOS Sonoma 14, watchOS 10, tvOS 17, Safari 17. The issue was addressed with improved memory handling.

CVEs:CVE-2023-42875

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
safari affected apple
tvos affected apple
watchos affected apple
Upstream advisory

CVE-2023-4736

OtherPoC exploitHIGH2023-09-02

Untrusted Search Path in GitHub repository vim/vim prior to 9.0.1833.

CVEs:CVE-2023-4736

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2023-41063

iPadOSPoC exploitCRITICAL2023-09-26

The issue was addressed with improved memory handling. This issue is fixed in macOS Ventura 13.6, tvOS 17, iOS 16.7 and iPadOS 16.7, iOS 17 and iPadOS 17, macOS Sonoma 14. An app may be able to execute arbitrary code with kernel privileges.

CVEs:CVE-2023-41063

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
Upstream advisory

CVE-2023-41968

iPadOSPoC exploitHIGH2023-09-26

This issue was addressed with improved validation of symlinks. This issue is fixed in macOS Ventura 13.6, tvOS 17, macOS Monterey 12.7, watchOS 10, iOS 17 and iPadOS 17, macOS Sonoma 14. An app may be able to read arbitrary files.

CVEs:CVE-2023-41968

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
tvos affected apple
watchos affected apple
Upstream advisory

CVE-2023-41981

iPadOSPoC exploitCRITICAL2023-09-26

The issue was addressed with improved memory handling. This issue is fixed in macOS Ventura 13.6, tvOS 17, iOS 16.7 and iPadOS 16.7, watchOS 10, iOS 17 and iPadOS 17, macOS Sonoma 14. An attacker that has already achieved kernel code execution may be a...

CVEs:CVE-2023-41981

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
tvos affected apple
watchos affected apple
Upstream advisory

CVE-2023-40452

iPadOSPoC exploitHIGH2023-09-26

The issue was addressed with improved bounds checks. This issue is fixed in macOS Ventura 13.6, tvOS 17, macOS Monterey 12.7, watchOS 10, iOS 17 and iPadOS 17, macOS Sonoma 14. An app may be able to overwrite arbitrary files.

CVEs:CVE-2023-40452

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
tvos affected apple
watchos affected apple
Upstream advisory

CVE-2023-40454

iPadOSPoC exploitHIGH2023-09-26

A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Ventura 13.6, tvOS 17, iOS 16.7 and iPadOS 16.7, macOS Monterey 12.7, watchOS 10, iOS 17 and iPadOS 17, macOS Sonoma 14. An app may be able to delete files for...

CVEs:CVE-2023-40454

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
tvos affected apple
watchos affected apple
Upstream advisory

CVE-2023-41065

iPadOSPoC exploitLOW2023-09-26

A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in tvOS 17, iOS 17 and iPadOS 17, watchOS 10, macOS Sonoma 14. An app may be able to read sensitive location information.

CVEs:CVE-2023-41065

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
tvos affected apple
watchos affected apple
Upstream advisory

CVE-2023-41071

iPadOSPoC exploitCRITICAL2023-09-26

A use-after-free issue was addressed with improved memory management. This issue is fixed in tvOS 17, iOS 17 and iPadOS 17, watchOS 10, macOS Ventura 13.6. An app may be able to execute arbitrary code with kernel privileges.

CVEs:CVE-2023-41071

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
tvos affected apple
watchos affected apple
Upstream advisory

CVE-2023-41073

iPadOSPoC exploitMEDIUM2023-09-26

An authorization issue was addressed with improved state management. This issue is fixed in macOS Ventura 13.6, tvOS 17, iOS 16.7 and iPadOS 16.7, macOS Monterey 12.7, watchOS 10, iOS 17 and iPadOS 17, macOS Sonoma 14. An app may be able to access prot...

CVEs:CVE-2023-41073

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
tvos affected apple
watchos affected apple
Upstream advisory

CVE-2023-40409

iPadOSPoC exploitCRITICAL2023-09-26

The issue was addressed with improved memory handling. This issue is fixed in macOS Ventura 13.6, tvOS 17, macOS Monterey 12.7, watchOS 10, iOS 17 and iPadOS 17. An app may be able to execute arbitrary code with kernel privileges.

CVEs:CVE-2023-40409

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
tvos affected apple
watchos affected apple
Upstream advisory

CVE-2023-40412

iPadOSPoC exploitCRITICAL2023-09-26

The issue was addressed with improved memory handling. This issue is fixed in macOS Ventura 13.6, tvOS 17, macOS Monterey 12.7, watchOS 10, iOS 17 and iPadOS 17. An app may be able to execute arbitrary code with kernel privileges.

CVEs:CVE-2023-40412

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
tvos affected apple
watchos affected apple
Upstream advisory

CVE-2023-32396

iPadOSPoC exploitHIGH2023-09-26

This issue was addressed with improved checks. This issue is fixed in Xcode 15, tvOS 17, watchOS 10, iOS 17 and iPadOS 17, macOS Sonoma 14. An app may be able to gain elevated privileges.

CVEs:CVE-2023-32396

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
tvos affected apple
watchos affected apple
xcode affected apple
Upstream advisory

CVE-2023-41068

iPadOSPoC exploitHIGH2023-09-26

An access issue was addressed with improved access restrictions. This issue is fixed in tvOS 17, iOS 17 and iPadOS 17, watchOS 10, iOS 16.7 and iPadOS 16.7. A user may be able to elevate privileges.

CVEs:CVE-2023-41068

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
tvos affected apple
watchos affected apple
Upstream advisory

CVE-2023-38596

iPadOSPoC exploitCRITICAL2023-09-26

The issue was addressed with improved handling of protocols. This issue is fixed in tvOS 17, iOS 17 and iPadOS 17, watchOS 10, macOS Sonoma 14. An app may fail to enforce App Transport Security.

CVEs:CVE-2023-38596

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
tvos affected apple
watchos affected apple
Upstream advisory

CVE-2023-40432

iPadOSPoC exploitCRITICAL2023-09-26

The issue was addressed with improved memory handling. This issue is fixed in tvOS 17, iOS 17 and iPadOS 17, watchOS 10, macOS Sonoma 14. An app may be able to execute arbitrary code with kernel privileges.

CVEs:CVE-2023-40432

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
tvos affected apple
watchos affected apple
Upstream advisory

CVE-2023-41070

iPadOSPoC exploitHIGH2023-09-26

A logic issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.6, iOS 16.7 and iPadOS 16.7, watchOS 10, iOS 17 and iPadOS 17, macOS Sonoma 14. An app may be able to access sensitive data logged when a user shares a link.

CVEs:CVE-2023-41070

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
watchos affected apple
Upstream advisory

CVE-2023-41174

iPadOSPoC exploitCRITICAL2023-09-26

The issue was addressed with improved memory handling. This issue is fixed in tvOS 17, iOS 17 and iPadOS 17, watchOS 10. An app may be able to execute arbitrary code with kernel privileges.

CVEs:CVE-2023-41174

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
tvos affected apple
watchos affected apple
Upstream advisory

CVE-2023-41066

macOSPoC exploitMEDIUM2023-09-26

An authentication issue was addressed with improved state management. This issue is fixed in macOS Sonoma 14. An app may be able to unexpectedly leak a user's credentials from secure text fields.

CVEs:CVE-2023-41066

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2023-40395

iPadOSPoC exploitLOW2023-09-26

The issue was addressed with improved handling of caches. This issue is fixed in tvOS 17, iOS 16.7 and iPadOS 16.7, macOS Monterey 12.7, watchOS 10, iOS 17 and iPadOS 17, macOS Sonoma 14. An app may be able to access contacts.

CVEs:CVE-2023-40395

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
tvos affected apple
watchos affected apple
Upstream advisory

CVE-2023-40391

iPadOSPoC exploitMEDIUM2023-09-26

The issue was addressed with improved memory handling. This issue is fixed in tvOS 17, iOS 17 and iPadOS 17, macOS Sonoma 14, Xcode 15. An app may be able to disclose kernel memory.

CVEs:CVE-2023-40391

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
tvos affected apple
xcode affected apple
Upstream advisory

CVE-2023-40399

iPadOSPoC exploitMEDIUM2023-09-26

The issue was addressed with improved memory handling. This issue is fixed in tvOS 17, iOS 17 and iPadOS 17, watchOS 10, macOS Sonoma 14. An app may be able to disclose kernel memory.

CVEs:CVE-2023-40399

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
tvos affected apple
watchos affected apple
Upstream advisory

CVE-2023-40424

iPadOSPoC exploitHIGH2023-09-26

The issue was addressed with improved checks. This issue is fixed in iOS 17 and iPadOS 17, watchOS 10, macOS Sonoma 14. An app may be able to access user-sensitive data.

CVEs:CVE-2023-40424

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
watchos affected apple
Upstream advisory

CVE-2023-40427

iPadOSPoC exploitLOW2023-09-26

The issue was addressed with improved handling of caches. This issue is fixed in macOS Ventura 13.6, tvOS 17, macOS Monterey 12.7, watchOS 10, iOS 17 and iPadOS 17, macOS Sonoma 14. An app may be able to read sensitive location information.

CVEs:CVE-2023-40427

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
tvos affected apple
watchos affected apple
Upstream advisory

CVE-2023-40384

iPadOSPoC exploitHIGH2023-09-26

A permissions issue was addressed with improved redaction of sensitive information. This issue is fixed in tvOS 17, iOS 17 and iPadOS 17, macOS Sonoma 14. An app may be able to read sensitive location information.

CVEs:CVE-2023-40384

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
tvos affected apple
Upstream advisory

CVE-2023-41232

iPadOSPoC exploitMEDIUM2023-09-26

An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Monterey 12.7, iOS 17 and iPadOS 17, macOS Ventura 13.6, iOS 16.7 and iPadOS 16.7. An app may be able to disclose kernel memory.

CVEs:CVE-2023-41232

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
Upstream advisory

CVE-2023-40410

iPadOSPoC exploitMEDIUM2023-09-26

An out-of-bounds read was addressed with improved input validation. This issue is fixed in macOS Ventura 13.6, tvOS 17, macOS Monterey 12.7, watchOS 10, iOS 17 and iPadOS 17, macOS Sonoma 14. An app may be able to disclose kernel memory.

CVEs:CVE-2023-40410

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
tvos affected apple
watchos affected apple
Upstream advisory

CVE-2023-40541

macOSPoC exploitMEDIUM2023-09-26

This issue was addressed by adding an additional prompt for user consent. This issue is fixed in macOS Sonoma 14. A shortcut may output sensitive user data without consent.

CVEs:CVE-2023-40541

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2023-41995

iPadOSPoC exploitCRITICAL2023-09-26

A use-after-free issue was addressed with improved memory management. This issue is fixed in iOS 17 and iPadOS 17, macOS Sonoma 14. An app may be able to execute arbitrary code with kernel privileges.

CVEs:CVE-2023-41995

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
Upstream advisory

CVE-2023-32377

macOSPoC exploitCRITICAL2023-09-26

A buffer overflow issue was addressed with improved memory handling. This issue is fixed in macOS Sonoma 14. An app may be able to execute arbitrary code with kernel privileges.

CVEs:CVE-2023-32377

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2023-41067

macOSPoC exploitMEDIUM2023-09-26

A logic issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14. An app may bypass Gatekeeper checks.

CVEs:CVE-2023-41067

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2023-32361

iPadOSPoC exploitHIGH2023-09-26

The issue was addressed with improved handling of caches. This issue is fixed in tvOS 17, iOS 17 and iPadOS 17, watchOS 10, macOS Sonoma 14. An app may be able to access user-sensitive data.

CVEs:CVE-2023-32361

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
tvos affected apple
watchos affected apple
Upstream advisory

CVE-2023-37448

macOSPoC exploitLOW2023-09-26

A lock screen issue was addressed with improved state management. This issue is fixed in macOS Sonoma 14. A user may be able to view restricted content from the lock screen.

CVEs:CVE-2023-37448

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2023-38615

macOSPoC exploitCRITICAL2023-09-26

The issue was addressed with improved memory handling. This issue is fixed in macOS Sonoma 14. An app may be able to execute arbitrary code with kernel privileges.

CVEs:CVE-2023-38615

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2023-40431

iPadOSPoC exploitCRITICAL2023-09-26

The issue was addressed with improved memory handling. This issue is fixed in iOS 17 and iPadOS 17. An app may be able to execute arbitrary code with kernel privileges.

CVEs:CVE-2023-40431

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
Upstream advisory

CVE-2023-35990

iPadOSPoC exploitLOW2023-09-26

The issue was addressed with improved checks. This issue is fixed in iOS 17 and iPadOS 17, watchOS 10, iOS 16.7 and iPadOS 16.7, macOS Sonoma 14. An app may be able to identify what other apps a user has installed.

CVEs:CVE-2023-35990

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
watchos affected apple
Upstream advisory

CVE-2023-40419

iPadOSPoC exploitHIGH2023-09-26

The issue was addressed with improved checks. This issue is fixed in tvOS 17, iOS 17 and iPadOS 17, watchOS 10. An app may be able to gain elevated privileges.

CVEs:CVE-2023-40419

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
tvos affected apple
watchos affected apple
Upstream advisory

CVE-2023-40456

iPadOSPoC exploitLOW2023-09-26

The issue was addressed with improved checks. This issue is fixed in tvOS 17, iOS 17 and iPadOS 17, watchOS 10. An app may be able to access edited photos saved to a temporary directory.

CVEs:CVE-2023-40456

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
tvos affected apple
watchos affected apple
Upstream advisory

CVE-2023-40520

iPadOSPoC exploitLOW2023-09-26

The issue was addressed with improved checks. This issue is fixed in tvOS 17, iOS 17 and iPadOS 17, watchOS 10. An app may be able to access edited photos saved to a temporary directory.

CVEs:CVE-2023-40520

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
tvos affected apple
watchos affected apple
Upstream advisory

CVE-2023-41079

macOSPoC exploitMEDIUM2023-09-26

The issue was addressed with improved permissions logic. This issue is fixed in macOS Sonoma 14. An app may be able to bypass Privacy preferences.

CVEs:CVE-2023-41079

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2023-41980

iPadOSPoC exploitMEDIUM2023-09-26

A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 17 and iPadOS 17, macOS Sonoma 14. An app may be able to bypass Privacy preferences.

CVEs:CVE-2023-41980

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
Upstream advisory

CVE-2023-40406

macOSPoC exploitHIGH2023-09-26

The issue was addressed with improved checks. This issue is fixed in macOS Monterey 12.7, macOS Ventura 13.6, macOS Sonoma 14. An app may be able to read arbitrary files.

CVEs:CVE-2023-40406

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2023-40402

macOSPoC exploitMEDIUM2023-09-26

A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sonoma 14. An app may be able to access sensitive user data.

CVEs:CVE-2023-40402

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2023-40428

iPadOSPoC exploitMEDIUM2023-09-26

The issue was addressed with improved handling of caches. This issue is fixed in iOS 17 and iPadOS 17. An app may be able to access sensitive user data.

CVEs:CVE-2023-40428

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
Upstream advisory

CVE-2023-40426

macOSPoC exploitMEDIUM2023-09-26

A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sonoma 14. An app may be able to bypass certain Privacy preferences.

CVEs:CVE-2023-40426

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2023-41078

macOSPoC exploitMEDIUM2023-09-26

An authorization issue was addressed with improved state management. This issue is fixed in macOS Sonoma 14. An app may be able to bypass certain Privacy preferences.

CVEs:CVE-2023-41078

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2023-40386

macOSPoC exploitLOW2023-09-26

A privacy issue was addressed with improved handling of temporary files. This issue is fixed in macOS Sonoma 14. An app may be able to access Notes attachments.

CVEs:CVE-2023-40386

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2023-40422

macOSPoC exploitHIGH2023-09-26

The issue was addressed with improved memory handling. This issue is fixed in macOS Sonoma 14. An app may be able to cause a denial-of-service.

CVEs:CVE-2023-40422

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2023-40434

iPadOSPoC exploitLOW2023-09-26

A configuration issue was addressed with additional restrictions. This issue is fixed in iOS 17 and iPadOS 17, macOS Sonoma 14. An app may be able to access a user's Photos Library.

CVEs:CVE-2023-40434

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
Upstream advisory

CVE-2023-41986

iPadOSPoC exploitMEDIUM2023-09-26

The issue was addressed with improved checks. This issue is fixed in iOS 17 and iPadOS 17, macOS Sonoma 14. An app may be able to modify protected parts of the file system.

CVEs:CVE-2023-41986

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
Upstream advisory

CVE-2023-41996

macOSPoC exploitMEDIUM2023-09-26

The issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.6. Apps that fail verification checks may still launch.

CVEs:CVE-2023-41996

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2023-40443

iPadOSPoC exploitCRITICAL2023-09-26

The issue was addressed with improved checks. This issue is fixed in iOS 17 and iPadOS 17. An app may be able to gain root privileges.

CVEs:CVE-2023-40443

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
Upstream advisory

CVE-2023-32421

macOSPoC exploitMEDIUM2023-09-26

A privacy issue was addressed with improved handling of temporary files. This issue is fixed in macOS Sonoma 14. An app may be able to observe unprotected user data.

CVEs:CVE-2023-32421

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2023-40528

iPadOSPoC exploitMEDIUM2023-09-26

This issue was addressed by removing the vulnerable code. This issue is fixed in tvOS 17, watchOS 10, macOS Sonoma 14, iOS 17 and iPadOS 17, macOS Ventura 13.6.4. An app may be able to bypass Privacy preferences.

CVEs:CVE-2023-40528

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
tvos affected apple
watchos affected apple
Upstream advisory

CVE-2023-29497

macOSPoC exploitLOW2023-09-26

A privacy issue was addressed with improved handling of temporary files. This issue is fixed in macOS Sonoma 14. An app may be able to access calendar data saved to a temporary directory.

CVEs:CVE-2023-29497

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2023-23495

macOSPoC exploitHIGH2023-09-26

A permissions issue was addressed with improved redaction of sensitive information. This issue is fixed in macOS Sonoma 14. An app may be able to access sensitive user data.

CVEs:CVE-2023-23495

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2023-42826

macOSPoC exploitCRITICAL2023-09-26

The issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14. Processing a file may lead to arbitrary code execution.

CVEs:CVE-2023-42826

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2023-40450

macOSPoC exploitMEDIUM2023-09-26

The issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14. An app may bypass Gatekeeper checks.

CVEs:CVE-2023-40450

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2023-38605

macOSPoC exploitHIGH2023-09-06

This issue was addressed with improved redaction of sensitive information. This issue is fixed in macOS Ventura 13.5. An app may be able to determine a user’s current location.

CVEs:CVE-2023-38605

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
Upstream advisory

CVE-2023-41979

macOSPoC exploitMEDIUM2023-09-26

A race condition was addressed with improved locking. This issue is fixed in macOS Sonoma 14. An app may be able to modify protected parts of the file system.

CVEs:CVE-2023-41979

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2023-44216

OtherCoalition ESS < 30%CRITICAL2023-09-27

PVRIC (PowerVR Image Compression) on Imagination 2018 and later GPU devices offers software-transparent compression that enables cross-origin pixel-stealing attacks against feTurbulence and feBlend in the SVG Filter specification, aka a GPU.zip issue. ...

CVEs:CVE-2023-44216

Affected products

ProductStatusVendorPackageEcosystem
m1_mac_mini affected apple
macos affected apple
Upstream advisory

CVE-2023-40418

watchOSCoalition ESS < 30%MEDIUM2023-09-27

An authentication issue was addressed with improved state management. This issue is fixed in watchOS 10. An Apple Watch Ultra may not lock when using the Depth app.

CVEs:CVE-2023-40418

Affected products

ProductStatusVendorPackageEcosystem
watchos affected apple
Upstream advisory

CVE-2023-40435

XcodeCoalition ESS < 30%MEDIUM2023-09-26

This issue was addressed by enabling hardened runtime. This issue is fixed in Xcode 15. An app may be able to access App Store credentials.

CVEs:CVE-2023-40435

Affected products

ProductStatusVendorPackageEcosystem
xcode affected apple
Upstream advisory

Need live exploit intelligence?

Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.