VDB
CVE-2023-40389
CVE-2023-40389
PUBLISHED
CVSS 5.5 MEDIUM
The issue was addressed with improved restriction of data container access. This issue is fixed in macOS Ventura 13.6.5, macOS Monterey 12.7.4. An app may be able to access sensitive user data.
EPSS 0.22% · 11.0th percentile
Risk Scores
CVSS 3.1
5.5
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
EPSS Score
0.22%
11.0th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| apple | macos | 0, 13.0 |
| Apple | macOS | unspecified, * |
Timeline
- Jun 10, 2024 CVE Published
- Jun 11, 2024 EPSS Score
- Jul 4, 2024 EPSS Score
- Jul 28, 2024 EPSS Score
- Aug 20, 2024 EPSS Score
- Sep 12, 2024 EPSS Score
- Oct 6, 2024 EPSS Score
- Oct 29, 2024 EPSS Score
- Nov 21, 2024 EPSS Score
- Dec 15, 2024 EPSS Score
- Jan 8, 2025 EPSS Score
- Jan 31, 2025 EPSS Score
References
- https://support.apple.com/kb/HT214035 advisory
- https://support.apple.com/kb/HT214036 advisory
- https://support.apple.com/en-us/HT214085 advisory
- https://support.apple.com/kb/HT214040 advisory
- https://support.apple.com/kb/HT214041 advisory
- https://support.apple.com/en-us/HT214083 advisory
- https://support.apple.com/kb/HT214085 advisory
- https://support.apple.com/kb/HT214083 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2023-40389 advisory