VDB
CVE-2023-42867
CVE-2023-42867
PUBLISHED
CVSS 7.800000190734863 HIGH
This issue was addressed with improved validation of the process entitlement and Team ID. This issue is fixed in GarageBand 10.4.9. An app may be able to gain root privileges.
EPSS 0.21% · 10.1th percentile
Risk Scores
CVSS 3.1
7.800000190734863
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS Score
0.21%
10.1th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| apple | garageband | 0 |
| Apple | GarageBand | unspecified |
Timeline
- Dec 20, 2024 EPSS Score
- Dec 20, 2024 CVE Published
- Dec 20, 2024 PoC Published
- Dec 20, 2024 PoC Published
- Jan 6, 2025 EPSS Score
- Jan 22, 2025 EPSS Score
- Feb 8, 2025 EPSS Score
- Feb 25, 2025 EPSS Score
- Mar 13, 2025 EPSS Score
- Mar 30, 2025 EPSS Score
- Apr 16, 2025 EPSS Score
- May 3, 2025 EPSS Score