First published: Mon Mar 27 2023(Updated: )
An out-of-bounds write issue was addressed with improved input validation. This issue is fixed in macOS Ventura 13.3, iOS 15.7.4 and iPadOS 15.7.4, macOS Monterey 12.6.4, macOS Big Sur 11.7.5. An app may be able to cause unexpected system termination or write kernel memory.
Credit: Tingting Yin Tsinghua UniversityTingting Yin Tsinghua UniversityTingting Yin Tsinghua UniversityTingting Yin Tsinghua University product-security@apple.com product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
Apple iOS | <15.7.4 | 15.7.4 |
Apple iPadOS | <15.7.4 | 15.7.4 |
Apple iPadOS | <15.7.4 | |
Apple iPhone OS | <15.7.4 | |
Apple macOS | <11.7.5 | |
Apple macOS | >=12.0<12.6.4 | |
Apple macOS | >=13.0<13.3 | |
<12.6.4 | 12.6.4 | |
<11.7.5 | 11.7.5 | |
Apple macOS Ventura | <13.3 | 13.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2023-27936 is an out-of-bounds write vulnerability in CommCenter that has been fixed with improved input validation.
CVE-2023-27936 affects macOS Ventura 13.3, iOS 15.7.4, iPadOS 15.7.4, macOS Monterey 12.6.4, and macOS Big Sur 11.7.5.
The severity of CVE-2023-27936 is high, with a CVSS score of 7.8.
To fix CVE-2023-27936, update your Apple devices to the following versions: macOS Ventura 13.3, iOS 15.7.4, iPadOS 15.7.4, macOS Monterey 12.6.4, or macOS Big Sur 11.7.5.
You can find more information about CVE-2023-27936 on the following references: [Apple Support - HT213675](https://support.apple.com/en-us/HT213675), [Apple Support - HT213673](https://support.apple.com/en-us/HT213673), [Apple Support - HT213670](https://support.apple.com/en-us/HT213670).