Apple Security Advisories · December 2023 — Apple Security Advisories
50 advisories 50 CVEs 1 EXPLOITED

Apple-vendor CVEs for 2023-12. Mirrored into Vulnetix VDB.

Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity). 1 is already weaponised in the wild — see the Exploited section.

What would you fix first?

The advisories below are ordered by the Vulnetix risk prioritization strategy: exploitation evidence first, scores second. On the interactive page you can switch to three other lenses.

Advisories

CVE-2023-48795

OtherExploitedVulnCheck KEV listedMEDIUM2023-12-18

The SSH transport protocol with certain OpenSSH extensions, found in OpenSSH before 9.6 and other products, allows remote attackers to bypass integrity checks such that some packets are omitted (from the extension negotiation message), and a client and...

CVEs:CVE-2023-48795

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2023-42910

macOSActive exploitation (sightings)CRITICAL2023-12-11

Multiple memory corruption issues were addressed with improved input validation. This issue is fixed in macOS Sonoma 14.2. Processing a maliciously crafted file may lead to unexpected app termination or arbitrary code execution.

CVEs:CVE-2023-42910

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2023-42906

macOSActive exploitation (sightings)CRITICAL2023-12-11

Multiple memory corruption issues were addressed with improved input validation. This issue is fixed in macOS Sonoma 14.2. Processing a maliciously crafted file may lead to unexpected app termination or arbitrary code execution.

CVEs:CVE-2023-42906

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2023-42923

iPadOSActive exploitation (sightings)MEDIUM2023-12-11

This issue was addressed through improved state management. This issue is fixed in iOS 17.2 and iPadOS 17.2. Private Browsing tabs may be accessed without authentication.

CVEs:CVE-2023-42923

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
Upstream advisory

CVE-2023-42914

iPadOSActive exploitation (sightings)MEDIUM2023-12-11

The issue was addressed with improved memory handling. This issue is fixed in macOS Sonoma 14.2, iOS 17.2 and iPadOS 17.2, watchOS 10.2, macOS Ventura 13.6.3, tvOS 17.2, iOS 16.7.3 and iPadOS 16.7.3, macOS Monterey 12.7.2. An app may be able to break o...

CVEs:CVE-2023-42914

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
tvos affected apple
watchos affected apple
Upstream advisory

CVE-2023-42898

iPadOSActive exploitation (sightings)CRITICAL2023-12-11

The issue was addressed with improved memory handling. This issue is fixed in macOS Sonoma 14.2, watchOS 10.2, iOS 17.2 and iPadOS 17.2, tvOS 17.2. Processing an image may lead to arbitrary code execution.

CVEs:CVE-2023-42898

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
tvos affected apple
watchos affected apple
Upstream advisory

CVE-2023-42902

macOSActive exploitation (sightings)CRITICAL2023-12-11

Multiple memory corruption issues were addressed with improved input validation. This issue is fixed in macOS Sonoma 14.2. Processing a maliciously crafted file may lead to unexpected app termination or arbitrary code execution.

CVEs:CVE-2023-42902

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2023-42899

iPadOSActive exploitation (sightings)CRITICAL2023-12-11

The issue was addressed with improved memory handling. This issue is fixed in macOS Sonoma 14.2, iOS 17.2 and iPadOS 17.2, watchOS 10.2, macOS Ventura 13.6.3, tvOS 17.2, iOS 16.7.3 and iPadOS 16.7.3, macOS Monterey 12.7.2. Processing an image may lead ...

CVEs:CVE-2023-42899

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
tvos affected apple
watchos affected apple
Upstream advisory

CVE-2023-42919

iPadOSActive exploitation (sightings)MEDIUM2023-12-11

A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in macOS Sonoma 14.2, iOS 17.2 and iPadOS 17.2, watchOS 10.2, macOS Ventura 13.6.3, iOS 16.7.3 and iPadOS 16.7.3, macOS Monterey 12.7.2. An app may ...

CVEs:CVE-2023-42919

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
Upstream advisory

CVE-2023-42884

iPadOSActive exploitation (sightings)HIGH2023-12-11

This issue was addressed with improved redaction of sensitive information. This issue is fixed in macOS Sonoma 14.2, iOS 17.2 and iPadOS 17.2, macOS Ventura 13.6.3, tvOS 17.2, iOS 16.7.3 and iPadOS 16.7.3. An app may be able to disclose kernel memory.

CVEs:CVE-2023-42884

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
tvos affected apple
Upstream advisory

CVE-2023-42897

iPadOSActive exploitation (sightings)MEDIUM2023-12-11

The issue was addressed with improved checks. This issue is fixed in iOS 17.2 and iPadOS 17.2. An attacker with physical access may be able to use Siri to access sensitive user data.

CVEs:CVE-2023-42897

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
Upstream advisory

CVE-2023-42922

iPadOSActive exploitation (sightings)HIGH2023-12-11

This issue was addressed with improved redaction of sensitive information. This issue is fixed in macOS Sonoma 14.2, iOS 17.2 and iPadOS 17.2, macOS Ventura 13.6.3, iOS 16.7.3 and iPadOS 16.7.3, macOS Monterey 12.7.2. An app may be able to read sensiti...

CVEs:CVE-2023-42922

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
Upstream advisory

CVE-2023-42926

macOSActive exploitation (sightings)CRITICAL2023-12-11

Multiple memory corruption issues were addressed with improved input validation. This issue is fixed in macOS Sonoma 14.2. Processing a maliciously crafted file may lead to unexpected app termination or arbitrary code execution.

CVEs:CVE-2023-42926

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2023-42882

macOSActive exploitation (sightings)CRITICAL2023-12-11

The issue was addressed with improved memory handling. This issue is fixed in macOS Sonoma 14.2. Processing an image may lead to arbitrary code execution.

CVEs:CVE-2023-42882

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2023-42874

macOSActive exploitation (sightings)LOW2023-12-11

This issue was addressed with improved state management. This issue is fixed in macOS Sonoma 14.2. Secure text fields may be displayed via the Accessibility Keyboard when using a physical keyboard.

CVEs:CVE-2023-42874

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2023-42891

macOSActive exploitation (sightings)MEDIUM2023-12-11

An authentication issue was addressed with improved state management. This issue is fixed in macOS Sonoma 14.2, macOS Ventura 13.6.3, macOS Monterey 12.7.2. An app may be able to monitor keystrokes without user permission.

CVEs:CVE-2023-42891

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2023-42901

macOSActive exploitation (sightings)CRITICAL2023-12-11

Multiple memory corruption issues were addressed with improved input validation. This issue is fixed in macOS Sonoma 14.2. Processing a maliciously crafted file may lead to unexpected app termination or arbitrary code execution.

CVEs:CVE-2023-42901

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2023-42903

macOSActive exploitation (sightings)CRITICAL2023-12-11

Multiple memory corruption issues were addressed with improved input validation. This issue is fixed in macOS Sonoma 14.2. Processing a maliciously crafted file may lead to unexpected app termination or arbitrary code execution.

CVEs:CVE-2023-42903

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2023-42907

macOSActive exploitation (sightings)CRITICAL2023-12-11

Multiple memory corruption issues were addressed with improved input validation. This issue is fixed in macOS Sonoma 14.2. Processing a maliciously crafted file may lead to unexpected app termination or arbitrary code execution.

CVEs:CVE-2023-42907

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2023-42908

macOSActive exploitation (sightings)CRITICAL2023-12-11

Multiple memory corruption issues were addressed with improved input validation. This issue is fixed in macOS Sonoma 14.2. Processing a maliciously crafted file may lead to unexpected app termination or arbitrary code execution.

CVEs:CVE-2023-42908

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2023-42909

macOSActive exploitation (sightings)CRITICAL2023-12-11

Multiple memory corruption issues were addressed with improved input validation. This issue is fixed in macOS Sonoma 14.2. Processing a maliciously crafted file may lead to unexpected app termination or arbitrary code execution.

CVEs:CVE-2023-42909

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2023-42911

macOSActive exploitation (sightings)CRITICAL2023-12-11

Multiple memory corruption issues were addressed with improved input validation. This issue is fixed in macOS Sonoma 14.2. Processing a maliciously crafted file may lead to unexpected app termination or arbitrary code execution.

CVEs:CVE-2023-42911

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2023-42912

macOSActive exploitation (sightings)CRITICAL2023-12-11

Multiple memory corruption issues were addressed with improved input validation. This issue is fixed in macOS Sonoma 14.2. Processing a maliciously crafted file may lead to unexpected app termination or arbitrary code execution.

CVEs:CVE-2023-42912

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2023-42894

macOSActive exploitation (sightings)HIGH2023-12-11

This issue was addressed with improved redaction of sensitive information. This issue is fixed in macOS Sonoma 14.2, macOS Ventura 13.6.3, macOS Monterey 12.7.2. An app may be able to access information about a user's contacts.

CVEs:CVE-2023-42894

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2023-42932

macOSActive exploitation (sightings)MEDIUM2023-12-11

A logic issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14.2, macOS Ventura 13.6.3, macOS Monterey 12.7.2. An app may be able to access protected user data.

CVEs:CVE-2023-42932

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2023-42886

macOSActive exploitation (sightings)CRITICAL2023-12-11

An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Sonoma 14.2, macOS Ventura 13.6.3, macOS Monterey 12.7.2. A user may be able to cause unexpected app termination or arbitrary code execution.

CVEs:CVE-2023-42886

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2023-42924

macOSActive exploitation (sightings)MEDIUM2023-12-11

A logic issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14.2, macOS Ventura 13.6.3. An app may be able to access sensitive user data.

CVEs:CVE-2023-42924

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2023-42941

iPadOSActive exploitation (sightings)MEDIUM2023-12-11

The issue was addressed with improved checks. This issue is fixed in iOS 17.2 and iPadOS 17.2. An attacker in a privileged network position may be able to perform a denial-of-service attack using crafted Bluetooth packets.

CVEs:CVE-2023-42941

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
Upstream advisory

CVE-2023-42881

macOSActive exploitation (sightings)CRITICAL2023-12-11

The issue was addressed with improved memory handling. This issue is fixed in macOS Sonoma 14.2. Processing a file may lead to unexpected app termination or arbitrary code execution.

CVEs:CVE-2023-42881

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2023-45866

OtherCoalition ESS > 63%MEDIUM2023-12-04

Bluetooth HID Hosts in BlueZ may permit an unauthenticated Peripheral role HID Device to initiate and establish an encrypted connection, and accept HID keyboard reports, potentially permitting injection of HID messages when no user interaction has occu...

CVEs:CVE-2023-45866

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
Upstream advisory

CVE-2023-42890

iPadOSPoC exploitCRITICAL2023-12-11

The issue was addressed with improved memory handling. This issue is fixed in Safari 17.2, macOS Sonoma 14.2, watchOS 10.2, iOS 17.2 and iPadOS 17.2, tvOS 17.2. Processing web content may lead to arbitrary code execution.

CVEs:CVE-2023-42890

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
safari affected apple
tvos affected apple
watchos affected apple
Upstream advisory

CVE-2023-42931

macOSPoC exploitCRITICAL2023-12-11

The issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.6.3, macOS Sonoma 14.2, macOS Monterey 12.7.2. A process may gain admin privileges without proper authentication.

CVEs:CVE-2023-42931

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2023-42950

iPadOSPoC exploitCRITICAL2023-12-11

A use after free issue was addressed with improved memory management. This issue is fixed in Safari 17.2, iOS 17.2 and iPadOS 17.2, tvOS 17.2, watchOS 10.2, macOS Sonoma 14.2. Processing maliciously crafted web content may lead to arbitrary code execut...

CVEs:CVE-2023-42950

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
safari affected apple
tvos affected apple
watchos affected apple
Upstream advisory

CVE-2023-42956

iPadOSPoC exploitHIGH2023-12-11

The issue was addressed with improved memory handling. This issue is fixed in Safari 17.2, iOS 17.2 and iPadOS 17.2, macOS Sonoma 14.2. Processing web content may lead to a denial-of-service.

CVEs:CVE-2023-42956

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
safari affected apple
Upstream advisory

CVE-2023-42962

iPadOSPoC exploitHIGH2023-12-11

This issue was addressed with improved checks This issue is fixed in iOS 17.2 and iPadOS 17.2, iOS 16.7.3 and iPadOS 16.7.3. A remote attacker may be able to cause a denial-of-service.

CVEs:CVE-2023-42962

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
Upstream advisory

CVE-2023-42883

iPadOSPoC exploitHIGH2023-12-11

The issue was addressed with improved memory handling. This issue is fixed in Safari 17.2, macOS Sonoma 14.2, iOS 17.2 and iPadOS 17.2, watchOS 10.2, tvOS 17.2, iOS 16.7.3 and iPadOS 16.7.3. Processing an image may lead to a denial-of-service.

CVEs:CVE-2023-42883

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
safari affected apple
tvos affected apple
watchos affected apple
Upstream advisory

CVE-2023-42940

macOSPoC exploitMEDIUM2023-12-19

A session rendering issue was addressed with improved session tracking. This issue is fixed in macOS Sonoma 14.2.1. A user who shares their screen may unintentionally share the incorrect content.

CVEs:CVE-2023-42940

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2023-42913

macOSPoC exploitHIGH2023-12-11

This issue was addressed through improved state management. This issue is fixed in macOS Sonoma 14.2. Remote Login sessions may be able to obtain full disk access permissions.

CVEs:CVE-2023-42913

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2023-42904

macOSPoC exploitCRITICAL2023-12-11

Multiple memory corruption issues were addressed with improved input validation. This issue is fixed in macOS Sonoma 14.2. Processing a maliciously crafted file may lead to unexpected app termination or arbitrary code execution.

CVEs:CVE-2023-42904

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2023-42905

macOSPoC exploitCRITICAL2023-12-11

Multiple memory corruption issues were addressed with improved input validation. This issue is fixed in macOS Sonoma 14.2. Processing a maliciously crafted file may lead to unexpected app termination or arbitrary code execution.

CVEs:CVE-2023-42905

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2023-42900

macOSPoC exploitHIGH2023-12-11

The issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14.2. An app may be able to access user-sensitive data.

CVEs:CVE-2023-42900

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2023-40446

iPadOSPoC exploitCRITICAL2023-12-12

The issue was addressed with improved memory handling. This issue is fixed in macOS Monterey 12.7.1, iOS 16.7.2 and iPadOS 16.7.2, iOS 17.1 and iPadOS 17.1. Processing maliciously crafted input may lead to arbitrary code execution in user-installed apps.

CVEs:CVE-2023-40446

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
Upstream advisory

CVE-2023-42893

iPadOSPoC exploitMEDIUM2023-12-11

A permissions issue was addressed by removing vulnerable code and adding additional checks. This issue is fixed in macOS Monterey 12.7.2, macOS Ventura 13.6.3, iOS 17.2 and iPadOS 17.2, iOS 16.7.3 and iPadOS 16.7.3, tvOS 17.2, watchOS 10.2, macOS Sonom...

CVEs:CVE-2023-42893

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
tvos affected apple
watchos affected apple
Upstream advisory

CVE-2023-42947

iPadOSPoC exploitHIGH2023-12-11

A path handling issue was addressed with improved validation. This issue is fixed in macOS Monterey 12.7.2, macOS Ventura 13.6.3, iOS 17.2 and iPadOS 17.2, tvOS 17.2, watchOS 10.2, macOS Sonoma 14.2. An app may be able to break out of its sandbox.

CVEs:CVE-2023-42947

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
tvos affected apple
watchos affected apple
Upstream advisory

CVE-2023-42936

iPadOSPoC exploitHIGH2023-12-11

This issue was addressed with improved redaction of sensitive information. This issue is fixed in macOS Monterey 12.7.2, macOS Ventura 13.6.3, iOS 17.2 and iPadOS 17.2, tvOS 17.2, watchOS 10.2, macOS Sonoma 14.2. An app may be able to access user-sensi...

CVEs:CVE-2023-42936

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
tvos affected apple
watchos affected apple
Upstream advisory

CVE-2023-42896

iPadOSPoC exploitMEDIUM2023-12-11

An issue was addressed with improved handling of temporary files. This issue is fixed in macOS Monterey 12.7.2, macOS Ventura 13.6.3, iOS 17.2 and iPadOS 17.2, iOS 16.7.3 and iPadOS 16.7.3, macOS Sonoma 14.2. An app may be able to modify protected part...

CVEs:CVE-2023-42896

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
Upstream advisory

CVE-2023-42930

macOSPoC exploitMEDIUM2023-12-11

This issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.6.3, macOS Sonoma 14.2, macOS Monterey 12.7.2. An app may be able to modify protected parts of the file system.

CVEs:CVE-2023-42930

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2023-40390

macOSPoC exploitHIGH2023-12-11

A privacy issue was addressed by moving sensitive data to a protected location. This issue is fixed in macOS Sonoma 14.2. An app may be able to access user-sensitive data.

CVEs:CVE-2023-40390

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2023-42892

macOSPoC exploitHIGH2023-12-11

A use-after-free issue was addressed with improved memory management. This issue is fixed in macOS Ventura 13.6.3, macOS Sonoma 14.2, macOS Monterey 12.7.2. A local attacker may be able to elevate their privileges.

CVEs:CVE-2023-42892

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2023-42974

iPadOSPoC exploitCRITICAL2023-12-11

A race condition was addressed with improved state handling. This issue is fixed in macOS Monterey 12.7.2, macOS Ventura 13.6.3, iOS 17.2 and iPadOS 17.2, iOS 16.7.3 and iPadOS 16.7.3, macOS Sonoma 14.2. An app may be able to execute arbitrary code wit...

CVEs:CVE-2023-42974

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
ipad_os affected apple
iphone_os affected apple
macos affected apple
Upstream advisory

Need live exploit intelligence?

Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.