VulnerabilityModified
CVE-2023-27940
The issue was addressed with additional permissions checks.
MEDIUM 6.3EPSS 0.25%
Does this matter?
Lower severity and a low EPSS score (0.25%). Track it; it rarely justifies an emergency change on its own.
Description
The issue was addressed with additional permissions checks. This issue is fixed in iOS 15.7.6 and iPadOS 15.7.6, macOS Monterey 12.6.6, macOS Ventura 13.4. A sandboxed app may be able to observe system-wide network connections.
- CVSS 3.1
- 6.3 MEDIUMCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N
- EPSS
- 0.25% probability · 17th percentile
- CISA KEV
- Not listed
- Affected
- apple/ipados · apple/iphone os · apple/macos
- Source
- product-security@apple.com
References
- https://support.apple.com/en-us/HT213758Release Notes, Vendor Advisory
- https://support.apple.com/en-us/HT213759Release Notes, Vendor Advisory
- https://support.apple.com/en-us/HT213765Release Notes, Vendor Advisory
- https://support.apple.com/en-us/HT213758Release Notes, Vendor Advisory
- https://support.apple.com/en-us/HT213759Release Notes, Vendor Advisory
- https://support.apple.com/en-us/HT213765Release Notes, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.