VulnerabilityModified
CVE-2023-42887
An app may be able to read arbitrary files.
MEDIUM 6.3EPSS 0.24%
Does this matter?
Lower severity and a low EPSS score (0.24%). Track it; it rarely justifies an emergency change on its own.
Description
An access issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Ventura 13.6.4, macOS Sonoma 14.2. An app may be able to read arbitrary files.
- CVSS 3.1
- 6.3 MEDIUMCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N
- EPSS
- 0.24% probability · 15th percentile
- CISA KEV
- Not listed
- Affected
- apple/macos
- Source
- product-security@apple.com
References
- http://seclists.org/fulldisclosure/2024/Jan/37Third Party Advisory
- https://support.apple.com/en-us/HT214036Release Notes, Vendor Advisory
- https://support.apple.com/en-us/HT214058Release Notes, Vendor Advisory
- https://support.apple.com/kb/HT214036Release Notes, Vendor Advisory
- http://seclists.org/fulldisclosure/2024/Jan/37Third Party Advisory
- https://support.apple.com/en-us/HT214036Release Notes, Vendor Advisory
- https://support.apple.com/en-us/HT214058Release Notes, Vendor Advisory
- https://support.apple.com/kb/HT214036Release Notes, Vendor Advisory
- https://support.apple.com/kb/HT214058
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.