CVE-2023-32434
HIGH
7,8
Source: [email protected]
Attack Vector: local
Attack Complexity: low
Privileges Required: none
User Interaction: required
Scope: unchanged
Confidentiality: high
Integrity: high
Availability: high
Description
AI Translation Available
An integer overflow was addressed with improved input validation. This issue is fixed in watchOS 9.5.2, macOS Big Sur 11.7.8, iOS 15.7.7 and iPadOS 15.7.7, macOS Monterey 12.6.7, watchOS 8.8.1, iOS 16.5.1 and iPadOS 16.5.1, macOS Ventura 13.4.1. An app may be able to execute arbitrary code with kernel privileges. Apple is aware of a report that this issue may have been actively exploited against versions of iOS released before iOS 15.7.
EPSS (Exploit Prediction Scoring System)
Trend Analysis
EPSS (Exploit Prediction Scoring System)
Prevede la probabilità di sfruttamento basata su intelligence sulle minacce e sulle caratteristiche della vulnerabilità.
EPSS Score
0,6421
Percentile
1,0th
Updated
EPSS Score Trend (Last 90 Days)
190
Integer Overflow or Wraparound
StableCommon Consequences
Security Scopes Affected:
Availability
Integrity
Confidentiality
Access Control
Other
Potential Impacts:
Dos: Crash, Exit, Or Restart
Dos: Resource Consumption (Memory)
Dos: Instability
Modify Memory
Execute Unauthorized Code Or Commands
Bypass Protection Mechanism
Alter Execution Logic
Dos: Resource Consumption (Cpu)
Applicable Platforms
Languages:
C, Not Language-Specific
Operating System
Iphone Os by Apple
Version Range Affected
From
16.0
(inclusive)
To
16.5.1
(exclusive)
CPE Identifier
View Detailed Analysis
cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System
Macos by Apple
Version Range Affected
From
13.0
(inclusive)
To
13.4.1
(exclusive)
CPE Identifier
View Detailed Analysis
cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System
Watchos by Apple
Version Range Affected
To
8.8.1
(exclusive)
CPE Identifier
View Detailed Analysis
cpe:2.3:o:apple:watchos:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System
Macos by Apple
Version Range Affected
From
12.0.0
(inclusive)
To
12.6.7
(exclusive)
CPE Identifier
View Detailed Analysis
cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System
Macos by Apple
Version Range Affected
From
11.0
(inclusive)
To
11.7.8
(exclusive)
CPE Identifier
View Detailed Analysis
cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System
Watchos by Apple
Version Range Affected
From
9.0
(inclusive)
To
9.5.2
(exclusive)
CPE Identifier
View Detailed Analysis
cpe:2.3:o:apple:watchos:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System
Iphone Os by Apple
Version Range Affected
To
15.7.7
(exclusive)
CPE Identifier
View Detailed Analysis
cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System
Ipados by Apple
Version Range Affected
From
16.0
(inclusive)
To
16.5.1
(exclusive)
CPE Identifier
View Detailed Analysis
cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System
Ipados by Apple
Version Range Affected
To
15.7.7
(exclusive)
CPE Identifier
View Detailed Analysis
cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023…
http://seclists.org/fulldisclosure/2023/Oct/20
https://support.apple.com/en-us/HT213808
https://support.apple.com/en-us/HT213809
https://support.apple.com/en-us/HT213810
https://support.apple.com/en-us/HT213811
https://support.apple.com/en-us/HT213812
https://support.apple.com/en-us/HT213813
https://support.apple.com/en-us/HT213814
https://support.apple.com/kb/HT213990
http://seclists.org/fulldisclosure/2023/Oct/20
https://support.apple.com/en-us/HT213808
https://support.apple.com/en-us/HT213809
https://support.apple.com/en-us/HT213810
https://support.apple.com/en-us/HT213811
https://support.apple.com/en-us/HT213812
https://support.apple.com/en-us/HT213813
https://support.apple.com/en-us/HT213814
https://support.apple.com/kb/HT213990