CVE-2023-40438

An issue was addressed with improved handling of temporary files. This issue is fixed in macOS Sonoma 14, iOS 16.7 and iPadOS 16.7. An app may be able to access edited photos saved to a temporary directory.
References
Link Resource
https://support.apple.com/en-us/HT213927 Release Notes Vendor Advisory
https://support.apple.com/en-us/HT213940 Release Notes Vendor Advisory
https://support.apple.com/en-us/HT213927 Release Notes Vendor Advisory
https://support.apple.com/en-us/HT213940 Release Notes Vendor Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*

History

20 Jun 2025, 16:15

Type Values Removed Values Added
CWE CWE-379

Information

Published : 2024-01-10 22:15

Updated : 2025-06-20 16:15


NVD link : CVE-2023-40438

Mitre link : CVE-2023-40438

CVE.ORG link : CVE-2023-40438


JSON object : View

Products Affected

apple

  • macos
  • iphone_os
  • ipados
CWE
NVD-CWE-noinfo CWE-379

Creation of Temporary File in Directory with Insecure Permissions