VulnerabilityModified
CVE-2023-27937
An integer overflow was addressed with improved input validation.
HIGH 7.8EPSS 0.26%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.26%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
An integer overflow was addressed with improved input validation. This issue is fixed in macOS Ventura 13.3, iOS 16.4 and iPadOS 16.4, macOS Big Sur 11.7.5, macOS Monterey 12.6.4, tvOS 16.4, watchOS 9.4. Parsing a maliciously crafted plist may lead to an unexpected app termination or arbitrary code execution.
- CVSS 3.1
- 7.8 HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
- EPSS
- 0.26% probability · 18th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-190
- Affected
- apple/ipados · apple/iphone os · apple/macos · apple/tvos · apple/watchos
- Source
- product-security@apple.com
References
- https://support.apple.com/en-us/HT213670Release Notes, Vendor Advisory
- https://support.apple.com/en-us/HT213674Release Notes, Vendor Advisory
- https://support.apple.com/en-us/HT213675Release Notes, Vendor Advisory
- https://support.apple.com/en-us/HT213676Release Notes, Vendor Advisory
- https://support.apple.com/en-us/HT213677Release Notes, Vendor Advisory
- https://support.apple.com/en-us/HT213678Release Notes, Vendor Advisory
- https://support.apple.com/en-us/HT213670Release Notes, Vendor Advisory
- https://support.apple.com/en-us/HT213674Release Notes, Vendor Advisory
- https://support.apple.com/en-us/HT213675Release Notes, Vendor Advisory
- https://support.apple.com/en-us/HT213676Release Notes, Vendor Advisory
- https://support.apple.com/en-us/HT213677Release Notes, Vendor Advisory
- https://support.apple.com/en-us/HT213678Release Notes, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.