5.5

CVE-2023-40528

This issue was addressed by removing the vulnerable code. This issue is fixed in tvOS 17, watchOS 10, macOS Sonoma 14, iOS 17 and iPadOS 17, macOS Ventura 13.6.4. An app may be able to bypass Privacy preferences.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Apple ≫ iPadOS Version < 17.0
Apple ≫ iPhone OS Version < 17.0
Apple ≫ macOS Version >= 13.0 < 13.6.4
Apple ≫ tvOS Version < 17.0
Apple ≫ watchOS Version < 10.0
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.24% 0.157
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 5.5 1.8 3.6
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
CISA-ADP 5.5 1.8 3.6
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
CWE-284 Improper Access Control

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

https://support.apple.com/kb/HT213940
Vendor Advisory
Release Notes
http://seclists.org/fulldisclosure/2024/Jan/37
Third Party Advisory
https://support.apple.com/kb/HT214058
https://support.apple.com/en-us/HT213940
Vendor Advisory
Release Notes
https://support.apple.com/en-us/HT213936
Vendor Advisory
Release Notes
https://support.apple.com/en-us/HT213937
Vendor Advisory
Release Notes
https://support.apple.com/en-us/HT213938
Vendor Advisory
Release Notes
https://support.apple.com/kb/HT213938
Vendor Advisory
Release Notes
https://support.apple.com/en-us/HT214058
Vendor Advisory
Release Notes
https://support.apple.com/kb/HT213936
Vendor Advisory
Release Notes
https://support.apple.com/kb/HT213937
Vendor Advisory
Release Notes