VulnerabilityModified
CVE-2023-42888
Processing a maliciously crafted image may result in disclosure of process memory.
MEDIUM 5.5EPSS 0.47%
Does this matter?
Lower severity and a low EPSS score (0.47%). Track it; it rarely justifies an emergency change on its own.
Description
The issue was addressed with improved checks. This issue is fixed in iOS 16.7.5 and iPadOS 16.7.5, watchOS 10.2, macOS Ventura 13.6.4, macOS Sonoma 14.2, macOS Monterey 12.7.3, iOS 17.2 and iPadOS 17.2. Processing a maliciously crafted image may result in disclosure of process memory.
- CVSS 3.1
- 5.5 MEDIUMCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
- EPSS
- 0.47% probability · 40th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-200
- Affected
- apple/ipados · apple/iphone os · apple/macos · apple/watchos
- Source
- product-security@apple.com
References
- http://seclists.org/fulldisclosure/2024/Jan/34Third Party Advisory
- http://seclists.org/fulldisclosure/2024/Jan/37Third Party Advisory
- http://seclists.org/fulldisclosure/2024/Jan/38Third Party Advisory
- https://support.apple.com/en-us/HT214035Release Notes, Vendor Advisory
- https://support.apple.com/en-us/HT214036Release Notes, Vendor Advisory
- https://support.apple.com/en-us/HT214041Release Notes, Vendor Advisory
- https://support.apple.com/en-us/HT214057Release Notes, Vendor Advisory
- https://support.apple.com/en-us/HT214058Release Notes, Vendor Advisory
- https://support.apple.com/en-us/HT214063Release Notes, Vendor Advisory
- https://support.apple.com/kb/HT214035Release Notes, Vendor Advisory
- https://support.apple.com/kb/HT214036Release Notes, Vendor Advisory
- https://support.apple.com/kb/HT214041Release Notes, Vendor Advisory
- http://seclists.org/fulldisclosure/2024/Jan/34Third Party Advisory
- http://seclists.org/fulldisclosure/2024/Jan/37Third Party Advisory
- http://seclists.org/fulldisclosure/2024/Jan/38Third Party Advisory
- https://support.apple.com/en-us/HT214035Release Notes, Vendor Advisory
- https://support.apple.com/en-us/HT214036Release Notes, Vendor Advisory
- https://support.apple.com/en-us/HT214041Release Notes, Vendor Advisory
- https://support.apple.com/en-us/HT214057Release Notes, Vendor Advisory
- https://support.apple.com/en-us/HT214058Release Notes, Vendor Advisory
- https://support.apple.com/en-us/HT214063Release Notes, Vendor Advisory
- https://support.apple.com/kb/HT214035Release Notes, Vendor Advisory
- https://support.apple.com/kb/HT214036Release Notes, Vendor Advisory
- https://support.apple.com/kb/HT214041Release Notes, Vendor Advisory
- https://support.apple.com/kb/HT214058
- https://support.apple.com/kb/HT214063
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.