Advisories
OtherExploitedVulnCheck KEV listedMEDIUM2023-12-18
The SSH transport protocol with certain OpenSSH extensions, found in OpenSSH before 9.6 and other products, allows remote attackers to bypass integrity checks such that some packets are omitted (from the extension negotiation message), and a client and...
CVEs:CVE-2023-48795
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| macos |
affected |
apple |
— |
— |
macOSActive exploitation (sightings)CRITICAL2023-12-11
Multiple memory corruption issues were addressed with improved input validation. This issue is fixed in macOS Sonoma 14.2. Processing a maliciously crafted file may lead to unexpected app termination or arbitrary code execution.
CVEs:CVE-2023-42910
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| macos |
affected |
apple |
— |
— |
macOSActive exploitation (sightings)CRITICAL2023-12-11
Multiple memory corruption issues were addressed with improved input validation. This issue is fixed in macOS Sonoma 14.2. Processing a maliciously crafted file may lead to unexpected app termination or arbitrary code execution.
CVEs:CVE-2023-42906
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| macos |
affected |
apple |
— |
— |
iPadOSActive exploitation (sightings)MEDIUM2023-12-11
This issue was addressed through improved state management. This issue is fixed in iOS 17.2 and iPadOS 17.2. Private Browsing tabs may be accessed without authentication.
CVEs:CVE-2023-42923
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| ipados |
affected |
apple |
— |
— |
| iphone_os |
affected |
apple |
— |
— |
iPadOSActive exploitation (sightings)MEDIUM2023-12-11
The issue was addressed with improved memory handling. This issue is fixed in macOS Sonoma 14.2, iOS 17.2 and iPadOS 17.2, watchOS 10.2, macOS Ventura 13.6.3, tvOS 17.2, iOS 16.7.3 and iPadOS 16.7.3, macOS Monterey 12.7.2. An app may be able to break o...
CVEs:CVE-2023-42914
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| ipados |
affected |
apple |
— |
— |
| iphone_os |
affected |
apple |
— |
— |
| macos |
affected |
apple |
— |
— |
| tvos |
affected |
apple |
— |
— |
| watchos |
affected |
apple |
— |
— |
iPadOSActive exploitation (sightings)CRITICAL2023-12-11
The issue was addressed with improved memory handling. This issue is fixed in macOS Sonoma 14.2, watchOS 10.2, iOS 17.2 and iPadOS 17.2, tvOS 17.2. Processing an image may lead to arbitrary code execution.
CVEs:CVE-2023-42898
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| ipados |
affected |
apple |
— |
— |
| iphone_os |
affected |
apple |
— |
— |
| macos |
affected |
apple |
— |
— |
| tvos |
affected |
apple |
— |
— |
| watchos |
affected |
apple |
— |
— |
macOSActive exploitation (sightings)CRITICAL2023-12-11
Multiple memory corruption issues were addressed with improved input validation. This issue is fixed in macOS Sonoma 14.2. Processing a maliciously crafted file may lead to unexpected app termination or arbitrary code execution.
CVEs:CVE-2023-42902
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| macos |
affected |
apple |
— |
— |
iPadOSActive exploitation (sightings)CRITICAL2023-12-11
The issue was addressed with improved memory handling. This issue is fixed in macOS Sonoma 14.2, iOS 17.2 and iPadOS 17.2, watchOS 10.2, macOS Ventura 13.6.3, tvOS 17.2, iOS 16.7.3 and iPadOS 16.7.3, macOS Monterey 12.7.2. Processing an image may lead ...
CVEs:CVE-2023-42899
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| ipados |
affected |
apple |
— |
— |
| iphone_os |
affected |
apple |
— |
— |
| macos |
affected |
apple |
— |
— |
| tvos |
affected |
apple |
— |
— |
| watchos |
affected |
apple |
— |
— |
iPadOSActive exploitation (sightings)MEDIUM2023-12-11
A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in macOS Sonoma 14.2, iOS 17.2 and iPadOS 17.2, watchOS 10.2, macOS Ventura 13.6.3, iOS 16.7.3 and iPadOS 16.7.3, macOS Monterey 12.7.2. An app may ...
CVEs:CVE-2023-42919
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| ipados |
affected |
apple |
— |
— |
| iphone_os |
affected |
apple |
— |
— |
| macos |
affected |
apple |
— |
— |
iPadOSActive exploitation (sightings)HIGH2023-12-11
This issue was addressed with improved redaction of sensitive information. This issue is fixed in macOS Sonoma 14.2, iOS 17.2 and iPadOS 17.2, macOS Ventura 13.6.3, tvOS 17.2, iOS 16.7.3 and iPadOS 16.7.3. An app may be able to disclose kernel memory.
CVEs:CVE-2023-42884
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| ipados |
affected |
apple |
— |
— |
| iphone_os |
affected |
apple |
— |
— |
| macos |
affected |
apple |
— |
— |
| tvos |
affected |
apple |
— |
— |
iPadOSActive exploitation (sightings)MEDIUM2023-12-11
The issue was addressed with improved checks. This issue is fixed in iOS 17.2 and iPadOS 17.2. An attacker with physical access may be able to use Siri to access sensitive user data.
CVEs:CVE-2023-42897
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| ipados |
affected |
apple |
— |
— |
| iphone_os |
affected |
apple |
— |
— |
iPadOSActive exploitation (sightings)HIGH2023-12-11
This issue was addressed with improved redaction of sensitive information. This issue is fixed in macOS Sonoma 14.2, iOS 17.2 and iPadOS 17.2, macOS Ventura 13.6.3, iOS 16.7.3 and iPadOS 16.7.3, macOS Monterey 12.7.2. An app may be able to read sensiti...
CVEs:CVE-2023-42922
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| ipados |
affected |
apple |
— |
— |
| iphone_os |
affected |
apple |
— |
— |
| macos |
affected |
apple |
— |
— |
macOSActive exploitation (sightings)CRITICAL2023-12-11
Multiple memory corruption issues were addressed with improved input validation. This issue is fixed in macOS Sonoma 14.2. Processing a maliciously crafted file may lead to unexpected app termination or arbitrary code execution.
CVEs:CVE-2023-42926
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| macos |
affected |
apple |
— |
— |
macOSActive exploitation (sightings)CRITICAL2023-12-11
The issue was addressed with improved memory handling. This issue is fixed in macOS Sonoma 14.2. Processing an image may lead to arbitrary code execution.
CVEs:CVE-2023-42882
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| macos |
affected |
apple |
— |
— |
macOSActive exploitation (sightings)LOW2023-12-11
This issue was addressed with improved state management. This issue is fixed in macOS Sonoma 14.2. Secure text fields may be displayed via the Accessibility Keyboard when using a physical keyboard.
CVEs:CVE-2023-42874
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| macos |
affected |
apple |
— |
— |
macOSActive exploitation (sightings)MEDIUM2023-12-11
An authentication issue was addressed with improved state management. This issue is fixed in macOS Sonoma 14.2, macOS Ventura 13.6.3, macOS Monterey 12.7.2. An app may be able to monitor keystrokes without user permission.
CVEs:CVE-2023-42891
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| macos |
affected |
apple |
— |
— |
macOSActive exploitation (sightings)CRITICAL2023-12-11
Multiple memory corruption issues were addressed with improved input validation. This issue is fixed in macOS Sonoma 14.2. Processing a maliciously crafted file may lead to unexpected app termination or arbitrary code execution.
CVEs:CVE-2023-42901
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| macos |
affected |
apple |
— |
— |
macOSActive exploitation (sightings)CRITICAL2023-12-11
Multiple memory corruption issues were addressed with improved input validation. This issue is fixed in macOS Sonoma 14.2. Processing a maliciously crafted file may lead to unexpected app termination or arbitrary code execution.
CVEs:CVE-2023-42903
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| macos |
affected |
apple |
— |
— |
macOSActive exploitation (sightings)CRITICAL2023-12-11
Multiple memory corruption issues were addressed with improved input validation. This issue is fixed in macOS Sonoma 14.2. Processing a maliciously crafted file may lead to unexpected app termination or arbitrary code execution.
CVEs:CVE-2023-42907
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| macos |
affected |
apple |
— |
— |
macOSActive exploitation (sightings)CRITICAL2023-12-11
Multiple memory corruption issues were addressed with improved input validation. This issue is fixed in macOS Sonoma 14.2. Processing a maliciously crafted file may lead to unexpected app termination or arbitrary code execution.
CVEs:CVE-2023-42908
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| macos |
affected |
apple |
— |
— |
macOSActive exploitation (sightings)CRITICAL2023-12-11
Multiple memory corruption issues were addressed with improved input validation. This issue is fixed in macOS Sonoma 14.2. Processing a maliciously crafted file may lead to unexpected app termination or arbitrary code execution.
CVEs:CVE-2023-42909
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| macos |
affected |
apple |
— |
— |
macOSActive exploitation (sightings)CRITICAL2023-12-11
Multiple memory corruption issues were addressed with improved input validation. This issue is fixed in macOS Sonoma 14.2. Processing a maliciously crafted file may lead to unexpected app termination or arbitrary code execution.
CVEs:CVE-2023-42911
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| macos |
affected |
apple |
— |
— |
macOSActive exploitation (sightings)CRITICAL2023-12-11
Multiple memory corruption issues were addressed with improved input validation. This issue is fixed in macOS Sonoma 14.2. Processing a maliciously crafted file may lead to unexpected app termination or arbitrary code execution.
CVEs:CVE-2023-42912
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| macos |
affected |
apple |
— |
— |
macOSActive exploitation (sightings)HIGH2023-12-11
This issue was addressed with improved redaction of sensitive information. This issue is fixed in macOS Sonoma 14.2, macOS Ventura 13.6.3, macOS Monterey 12.7.2. An app may be able to access information about a user's contacts.
CVEs:CVE-2023-42894
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| macos |
affected |
apple |
— |
— |
macOSActive exploitation (sightings)MEDIUM2023-12-11
A logic issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14.2, macOS Ventura 13.6.3, macOS Monterey 12.7.2. An app may be able to access protected user data.
CVEs:CVE-2023-42932
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| macos |
affected |
apple |
— |
— |
macOSActive exploitation (sightings)CRITICAL2023-12-11
An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Sonoma 14.2, macOS Ventura 13.6.3, macOS Monterey 12.7.2. A user may be able to cause unexpected app termination or arbitrary code execution.
CVEs:CVE-2023-42886
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| macos |
affected |
apple |
— |
— |
macOSActive exploitation (sightings)MEDIUM2023-12-11
A logic issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14.2, macOS Ventura 13.6.3. An app may be able to access sensitive user data.
CVEs:CVE-2023-42924
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| macos |
affected |
apple |
— |
— |
iPadOSActive exploitation (sightings)MEDIUM2023-12-11
The issue was addressed with improved checks. This issue is fixed in iOS 17.2 and iPadOS 17.2. An attacker in a privileged network position may be able to perform a denial-of-service attack using crafted Bluetooth packets.
CVEs:CVE-2023-42941
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| ipados |
affected |
apple |
— |
— |
| iphone_os |
affected |
apple |
— |
— |
macOSActive exploitation (sightings)CRITICAL2023-12-11
The issue was addressed with improved memory handling. This issue is fixed in macOS Sonoma 14.2. Processing a file may lead to unexpected app termination or arbitrary code execution.
CVEs:CVE-2023-42881
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| macos |
affected |
apple |
— |
— |
OtherCoalition ESS > 63%MEDIUM2023-12-04
Bluetooth HID Hosts in BlueZ may permit an unauthenticated Peripheral role HID Device to initiate and establish an encrypted connection, and accept HID keyboard reports, potentially permitting injection of HID messages when no user interaction has occu...
CVEs:CVE-2023-45866
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| ipados |
affected |
apple |
— |
— |
| iphone_os |
affected |
apple |
— |
— |
| macos |
affected |
apple |
— |
— |
iPadOSPoC exploitCRITICAL2023-12-11
The issue was addressed with improved memory handling. This issue is fixed in Safari 17.2, macOS Sonoma 14.2, watchOS 10.2, iOS 17.2 and iPadOS 17.2, tvOS 17.2. Processing web content may lead to arbitrary code execution.
CVEs:CVE-2023-42890
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| ipados |
affected |
apple |
— |
— |
| iphone_os |
affected |
apple |
— |
— |
| macos |
affected |
apple |
— |
— |
| safari |
affected |
apple |
— |
— |
| tvos |
affected |
apple |
— |
— |
| watchos |
affected |
apple |
— |
— |
macOSPoC exploitCRITICAL2023-12-11
The issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.6.3, macOS Sonoma 14.2, macOS Monterey 12.7.2. A process may gain admin privileges without proper authentication.
CVEs:CVE-2023-42931
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| macos |
affected |
apple |
— |
— |
iPadOSPoC exploitCRITICAL2023-12-11
A use after free issue was addressed with improved memory management. This issue is fixed in Safari 17.2, iOS 17.2 and iPadOS 17.2, tvOS 17.2, watchOS 10.2, macOS Sonoma 14.2. Processing maliciously crafted web content may lead to arbitrary code execut...
CVEs:CVE-2023-42950
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| ipados |
affected |
apple |
— |
— |
| iphone_os |
affected |
apple |
— |
— |
| macos |
affected |
apple |
— |
— |
| safari |
affected |
apple |
— |
— |
| tvos |
affected |
apple |
— |
— |
| watchos |
affected |
apple |
— |
— |
iPadOSPoC exploitHIGH2023-12-11
The issue was addressed with improved memory handling. This issue is fixed in Safari 17.2, iOS 17.2 and iPadOS 17.2, macOS Sonoma 14.2. Processing web content may lead to a denial-of-service.
CVEs:CVE-2023-42956
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| ipados |
affected |
apple |
— |
— |
| iphone_os |
affected |
apple |
— |
— |
| macos |
affected |
apple |
— |
— |
| safari |
affected |
apple |
— |
— |
iPadOSPoC exploitHIGH2023-12-11
This issue was addressed with improved checks This issue is fixed in iOS 17.2 and iPadOS 17.2, iOS 16.7.3 and iPadOS 16.7.3. A remote attacker may be able to cause a denial-of-service.
CVEs:CVE-2023-42962
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| ipados |
affected |
apple |
— |
— |
| iphone_os |
affected |
apple |
— |
— |
iPadOSPoC exploitHIGH2023-12-11
The issue was addressed with improved memory handling. This issue is fixed in Safari 17.2, macOS Sonoma 14.2, iOS 17.2 and iPadOS 17.2, watchOS 10.2, tvOS 17.2, iOS 16.7.3 and iPadOS 16.7.3. Processing an image may lead to a denial-of-service.
CVEs:CVE-2023-42883
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| ipados |
affected |
apple |
— |
— |
| iphone_os |
affected |
apple |
— |
— |
| macos |
affected |
apple |
— |
— |
| safari |
affected |
apple |
— |
— |
| tvos |
affected |
apple |
— |
— |
| watchos |
affected |
apple |
— |
— |
macOSPoC exploitMEDIUM2023-12-19
A session rendering issue was addressed with improved session tracking. This issue is fixed in macOS Sonoma 14.2.1. A user who shares their screen may unintentionally share the incorrect content.
CVEs:CVE-2023-42940
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| macos |
affected |
apple |
— |
— |
macOSPoC exploitHIGH2023-12-11
This issue was addressed through improved state management. This issue is fixed in macOS Sonoma 14.2. Remote Login sessions may be able to obtain full disk access permissions.
CVEs:CVE-2023-42913
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| macos |
affected |
apple |
— |
— |
macOSPoC exploitCRITICAL2023-12-11
Multiple memory corruption issues were addressed with improved input validation. This issue is fixed in macOS Sonoma 14.2. Processing a maliciously crafted file may lead to unexpected app termination or arbitrary code execution.
CVEs:CVE-2023-42904
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| macos |
affected |
apple |
— |
— |
macOSPoC exploitCRITICAL2023-12-11
Multiple memory corruption issues were addressed with improved input validation. This issue is fixed in macOS Sonoma 14.2. Processing a maliciously crafted file may lead to unexpected app termination or arbitrary code execution.
CVEs:CVE-2023-42905
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| macos |
affected |
apple |
— |
— |
macOSPoC exploitHIGH2023-12-11
The issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14.2. An app may be able to access user-sensitive data.
CVEs:CVE-2023-42900
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| macos |
affected |
apple |
— |
— |
iPadOSPoC exploitCRITICAL2023-12-12
The issue was addressed with improved memory handling. This issue is fixed in macOS Monterey 12.7.1, iOS 16.7.2 and iPadOS 16.7.2, iOS 17.1 and iPadOS 17.1. Processing maliciously crafted input may lead to arbitrary code execution in user-installed apps.
CVEs:CVE-2023-40446
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| ipados |
affected |
apple |
— |
— |
| iphone_os |
affected |
apple |
— |
— |
| macos |
affected |
apple |
— |
— |
iPadOSPoC exploitMEDIUM2023-12-11
A permissions issue was addressed by removing vulnerable code and adding additional checks. This issue is fixed in macOS Monterey 12.7.2, macOS Ventura 13.6.3, iOS 17.2 and iPadOS 17.2, iOS 16.7.3 and iPadOS 16.7.3, tvOS 17.2, watchOS 10.2, macOS Sonom...
CVEs:CVE-2023-42893
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| ipados |
affected |
apple |
— |
— |
| iphone_os |
affected |
apple |
— |
— |
| macos |
affected |
apple |
— |
— |
| tvos |
affected |
apple |
— |
— |
| watchos |
affected |
apple |
— |
— |
iPadOSPoC exploitHIGH2023-12-11
A path handling issue was addressed with improved validation. This issue is fixed in macOS Monterey 12.7.2, macOS Ventura 13.6.3, iOS 17.2 and iPadOS 17.2, tvOS 17.2, watchOS 10.2, macOS Sonoma 14.2. An app may be able to break out of its sandbox.
CVEs:CVE-2023-42947
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| ipados |
affected |
apple |
— |
— |
| iphone_os |
affected |
apple |
— |
— |
| macos |
affected |
apple |
— |
— |
| tvos |
affected |
apple |
— |
— |
| watchos |
affected |
apple |
— |
— |
iPadOSPoC exploitHIGH2023-12-11
This issue was addressed with improved redaction of sensitive information. This issue is fixed in macOS Monterey 12.7.2, macOS Ventura 13.6.3, iOS 17.2 and iPadOS 17.2, tvOS 17.2, watchOS 10.2, macOS Sonoma 14.2. An app may be able to access user-sensi...
CVEs:CVE-2023-42936
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| ipados |
affected |
apple |
— |
— |
| iphone_os |
affected |
apple |
— |
— |
| macos |
affected |
apple |
— |
— |
| tvos |
affected |
apple |
— |
— |
| watchos |
affected |
apple |
— |
— |
iPadOSPoC exploitMEDIUM2023-12-11
An issue was addressed with improved handling of temporary files. This issue is fixed in macOS Monterey 12.7.2, macOS Ventura 13.6.3, iOS 17.2 and iPadOS 17.2, iOS 16.7.3 and iPadOS 16.7.3, macOS Sonoma 14.2. An app may be able to modify protected part...
CVEs:CVE-2023-42896
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| ipados |
affected |
apple |
— |
— |
| iphone_os |
affected |
apple |
— |
— |
| macos |
affected |
apple |
— |
— |
macOSPoC exploitMEDIUM2023-12-11
This issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.6.3, macOS Sonoma 14.2, macOS Monterey 12.7.2. An app may be able to modify protected parts of the file system.
CVEs:CVE-2023-42930
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| macos |
affected |
apple |
— |
— |
macOSPoC exploitHIGH2023-12-11
A privacy issue was addressed by moving sensitive data to a protected location. This issue is fixed in macOS Sonoma 14.2. An app may be able to access user-sensitive data.
CVEs:CVE-2023-40390
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| macos |
affected |
apple |
— |
— |
macOSPoC exploitHIGH2023-12-11
A use-after-free issue was addressed with improved memory management. This issue is fixed in macOS Ventura 13.6.3, macOS Sonoma 14.2, macOS Monterey 12.7.2. A local attacker may be able to elevate their privileges.
CVEs:CVE-2023-42892
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| macos |
affected |
apple |
— |
— |
iPadOSPoC exploitCRITICAL2023-12-11
A race condition was addressed with improved state handling. This issue is fixed in macOS Monterey 12.7.2, macOS Ventura 13.6.3, iOS 17.2 and iPadOS 17.2, iOS 16.7.3 and iPadOS 16.7.3, macOS Sonoma 14.2. An app may be able to execute arbitrary code wit...
CVEs:CVE-2023-42974
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| ipados |
affected |
apple |
— |
— |
| ipad_os |
affected |
apple |
— |
— |
| iphone_os |
affected |
apple |
— |
— |
| macos |
affected |
apple |
— |
— |