CVE-2023-38602
In Apple macOS existieren mehrere Schwachstellen. Der Fehler besteht in den Komponenten Apple Neural Engine, AppleMobileFileIntegrity, AppSandbox, Assets, curl, Find My, Grapher, Kernel, libxpc, Model I/O, OpenLDAP, PackageKit, Shortcuts, sips, SystemMigration, Voice Memos, Webkit, WebKit Process Model und WebKit Web Inspector u. a. aufgrund von Out-of-bounds-Reads, Pufferüberläufen und Use-after-free-Fehlern. Ein Angreifer kann diese Schwachstellen ausnutzen, um beliebigen Code auszuführen, Sicherheitsmaßnahmen zu umgehen, vertrauliche Informationen offenzulegen, einen Denial-of-Service-Zustand herbeizuführen und seine Privilegien zu erweitern. Die erfolgreiche Ausnutzung einiger dieser Schwachstellen erfordert eine Benutzerinteraktion.
EPSS 0.03% · 8.2th percentile
Risk Scores
Exploit Intelligence
- https://support.apple.com/en-us/HT213847 (circl)
- https://support.apple.com/en-us/HT213846 (circl)
- https://support.apple.com/en-us/HT213841 (circl)
- https://support.apple.com/en-us/HT213843 (circl)
- https://support.apple.com/en-us/HT213848 (circl)
- http://www.openwall.com/lists/oss-security/2023/08/02/1 (circl)
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/KJ4DG5LHWG2INDOTPB7MO4JVJN6LKL3M/ (circl)
- https://www.debian.org/security/2023/dsa-5468 (circl)
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/KQXJYKTGLKI6TJEFJCKPHCNY7PS72OER/ (circl)
- https://security.gentoo.org/glsa/202401-04 (circl)
…and 15 more exploits
Timeline
- Jul 24, 2023 CVE Published
- Jul 27, 2023 EPSS Score
- Aug 30, 2023 EPSS Score
- Sep 11, 2023 CVE Updated
- Oct 3, 2023 EPSS Score
- Nov 6, 2023 EPSS Score
- Dec 10, 2023 EPSS Score
- Jan 13, 2024 EPSS Score
- Feb 16, 2024 EPSS Score
- Mar 21, 2024 EPSS Score
- Apr 25, 2024 EPSS Score
- May 9, 2024 PoC Published
References
- https://support.apple.com/en-us/HT213843 advisory
- https://wid.cert-bund.de/.well-known/csaf/white/2023/wid-sec-w-2023-1880.json advisory
- https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2023-1880 advisory
- https://support.apple.com/en-us/HT213845 advisory
- https://support.apple.com/en-us/HT213844 advisory