Lucene search

K
cvelistAppleCVELIST:CVE-2023-23520
HistoryFeb 27, 2023 - 12:00 a.m.

CVE-2023-23520

2023-02-2700:00:00
apple
www.cve.org
2
race condition
validation
watchos
tvos
macos ventura
ios
ipados
arbitrary files
root

6.2 Medium

AI Score

Confidence

High

0.002 Low

EPSS

Percentile

52.2%

A race condition was addressed with additional validation. This issue is fixed in watchOS 9.3, tvOS 16.3, macOS Ventura 13.2, iOS 16.3 and iPadOS 16.3. A user may be able to read arbitrary files as root.

CNA Affected

[
  {
    "vendor": "Apple",
    "product": "iOS and iPadOS",
    "versions": [
      {
        "version": "unspecified",
        "status": "affected",
        "lessThan": "16.3",
        "versionType": "custom"
      }
    ]
  },
  {
    "vendor": "Apple",
    "product": "tvOS",
    "versions": [
      {
        "version": "unspecified",
        "status": "affected",
        "lessThan": "16.3",
        "versionType": "custom"
      }
    ]
  },
  {
    "vendor": "Apple",
    "product": "macOS",
    "versions": [
      {
        "version": "unspecified",
        "status": "affected",
        "lessThan": "13.2",
        "versionType": "custom"
      }
    ]
  },
  {
    "vendor": "Apple",
    "product": "watchOS",
    "versions": [
      {
        "version": "unspecified",
        "status": "affected",
        "lessThan": "9.3",
        "versionType": "custom"
      }
    ]
  }
]

6.2 Medium

AI Score

Confidence

High

0.002 Low

EPSS

Percentile

52.2%

Related for CVELIST:CVE-2023-23520