5.5

CVE-2023-23503

A logic issue was addressed with improved state management. This issue is fixed in macOS Ventura 13.2, iOS 16.3 and iPadOS 16.3, iOS 15.7.3 and iPadOS 15.7.3, tvOS 16.3, watchOS 9.3. An app may be able to bypass Privacy preferences.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Apple ≫ iPadOS Version < 15.7.3
Apple ≫ iPadOS Version >= 16.0 < 16.3
Apple ≫ iPhone OS Version < 15.7.3
Apple ≫ iPhone OS Version >= 16.0 < 16.3
Apple ≫ macOS Version < 13.2
Apple ≫ tvOS Version < 16.3
Apple ≫ watchOS Version < 9.3
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.22% 0.12
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 5.5 1.8 3.6
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
CWE-288 Authentication Bypass Using an Alternate Path or Channel

The product requires authentication, but the product has an alternate path or channel that does not require authentication.

https://support.apple.com/en-us/HT213605
Vendor Advisory
Release Notes
https://support.apple.com/en-us/HT213599
Vendor Advisory
Release Notes
https://support.apple.com/en-us/HT213601
Vendor Advisory
Release Notes
https://support.apple.com/en-us/HT213606
Vendor Advisory
Release Notes
https://support.apple.com/en-us/HT213598
Vendor Advisory
Release Notes