CVE-2023-42873

The issue was addressed with improved bounds checks. This issue is fixed in macOS Sonoma 14.1, tvOS 17.1, macOS Monterey 12.7.1, iOS 16.7.2 and iPadOS 16.7.2, iOS 17.1 and iPadOS 17.1, macOS Ventura 13.6.1. An app may be able to execute arbitrary code with kernel privileges.
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:apple:ipad_os:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:ipad_os:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:14.0:*:*:*:*:*:*:*
cpe:2.3:o:apple:tvos:*:*:*:*:*:*:*:*

History

26 Mar 2025, 21:15

Type Values Removed Values Added
CWE CWE-787

09 Dec 2024, 17:22

Type Values Removed Values Added
CPE cpe:2.3:o:apple:macos:14.0:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:ipad_os:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:tvos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*
First Time Apple macos
Apple iphone Os
Apple ipad Os
Apple
Apple tvos
CWE NVD-CWE-noinfo
References () https://support.apple.com/en-us/HT213981 - () https://support.apple.com/en-us/HT213981 - Vendor Advisory
References () https://support.apple.com/en-us/HT213982 - () https://support.apple.com/en-us/HT213982 - Vendor Advisory
References () https://support.apple.com/en-us/HT213983 - () https://support.apple.com/en-us/HT213983 - Vendor Advisory
References () https://support.apple.com/en-us/HT213984 - () https://support.apple.com/en-us/HT213984 - Vendor Advisory
References () https://support.apple.com/en-us/HT213985 - () https://support.apple.com/en-us/HT213985 - Vendor Advisory
References () https://support.apple.com/en-us/HT213987 - () https://support.apple.com/en-us/HT213987 - Vendor Advisory

Information

Published : 2024-02-21 07:15

Updated : 2025-03-26 21:15


NVD link : CVE-2023-42873

Mitre link : CVE-2023-42873

CVE.ORG link : CVE-2023-42873


JSON object : View

Products Affected

apple

  • tvos
  • iphone_os
  • macos
  • ipad_os
CWE
NVD-CWE-noinfo CWE-787

Out-of-bounds Write