VulnerabilityModified
CVE-2023-40435
This issue was addressed by enabling hardened runtime.
MEDIUM 5.5EPSS 0.24%
Does this matter?
Lower severity and a low EPSS score (0.24%). Track it; it rarely justifies an emergency change on its own.
Description
This issue was addressed by enabling hardened runtime. This issue is fixed in Xcode 15. An app may be able to access App Store credentials.
- CVSS 3.1
- 5.5 MEDIUMCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
- EPSS
- 0.24% probability · 15th percentile
- CISA KEV
- Not listed
- Affected
- apple/xcode
- Source
- product-security@apple.com
References
- http://seclists.org/fulldisclosure/2023/Oct/7Mailing List, Third Party Advisory
- https://support.apple.com/en-us/HT213939Release Notes, Vendor Advisory
- http://seclists.org/fulldisclosure/2023/Oct/7Mailing List, Third Party Advisory
- https://support.apple.com/en-us/HT213939Release Notes, Vendor Advisory
- https://support.apple.com/kb/HT213939
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.