VulnerabilityModified
CVE-2023-41077
An app may be able to access protected user data.
MEDIUM 5.5EPSS 0.28%
Does this matter?
Lower severity and a low EPSS score (0.28%). Track it; it rarely justifies an emergency change on its own.
Description
An app may be able to access protected user data. This issue is fixed in macOS Sonoma 14, macOS Ventura 13.6.1. The issue was addressed with improved checks.
- CVSS 3.1
- 5.5 MEDIUMCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
- EPSS
- 0.28% probability · 20th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-863
- Affected
- apple/macos
- Source
- product-security@apple.com
References
- https://support.apple.com/en-us/109050
- https://support.apple.com/en-us/120950
- http://seclists.org/fulldisclosure/2023/Oct/26Mailing List, Third Party Advisory
- https://support.apple.com/en-us/HT213985Release Notes, Vendor Advisory
- https://support.apple.com/kb/HT213985Release Notes, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.