VDB
CVE-2023-42867
CVE-2023-42867
PUBLISHED
CVSS 7.800000190734863 HIGH
This issue was addressed with improved validation of the process entitlement and Team ID. This issue is fixed in GarageBand 10.4.9. An app may be able to gain root privileges.
EPSS 0.21% · 11.4th percentile
Risk Scores
CVSS 3.1
7.800000190734863
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS Score
0.21%
11.4th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| apple | garageband | 0 |
| Apple | GarageBand | unspecified |
Timeline
- Dec 20, 2024 EPSS Score
- Dec 20, 2024 CVE Published
- Dec 20, 2024 PoC Published
- Dec 20, 2024 PoC Published
- Jan 5, 2025 EPSS Score
- Jan 22, 2025 EPSS Score
- Feb 7, 2025 EPSS Score
- Feb 24, 2025 EPSS Score
- Mar 12, 2025 EPSS Score
- Mar 29, 2025 EPSS Score
- Apr 14, 2025 EPSS Score
- May 1, 2025 EPSS Score