VulnerabilityModified
CVE-2023-28207
The issue was addressed with improved checks.
MEDIUM 5.5EPSS 0.16%
Does this matter?
Lower severity and a low EPSS score (0.16%). Track it; it rarely justifies an emergency change on its own.
Description
The issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.3, macOS Monterey 12.6.4, macOS Big Sur 11.7.5. A plug-in may be able to inherit app permissions and access user data.
- CVSS 3.1
- 5.5 MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 0.16% probability · 6th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-277
- Affected
- apple/macos
- Source
- product-security@apple.com
References
- https://support.apple.com/en-us/102784Release Notes, Vendor Advisory
- https://support.apple.com/en-us/102833Release Notes, Vendor Advisory
- https://support.apple.com/en-us/120945Release Notes, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.