First published: Mon Mar 27 2023(Updated: )
AMD. A buffer overflow issue was addressed with improved memory handling.
Credit: jzhu Trend Micro Zero Day InitiativeMeysam Firouzi @R00tkitSMM Mbition MercedesMeysam Firouzi @R00tkitSMM Mbition MercedesMickey Jin @patch1t Xin Huang @11iaxH CVE-2023-0049 CVE-2023-0051 CVE-2023-0054 CVE-2023-0288 CVE-2023-0433 CVE-2023-0512 Gertjan Franken imecKU Leuven hazbinhotel Trend Micro Zero Day InitiativeGeorgy Kucherin @kucher1n KasperskyLeonid Bezvershenko @bzvr_ KasperskyBoris Larin @oct0xor Kaspersky KasperskyValentin Pashkov Kasperskyan anonymous researcher Anonymous Trend Micro Zero Day InitiativeDohyun Lee @l33d0hyun SSD Labscrixer @pwning_me SSD LabsABC Research s.r.o. Mohamed Ghannam @_simo36 Adam M. Brandon Dalton @partyD0lphin Red CanaryChan Shue Long Offensive Security Offensive SecurityCsaba Fitzl @theevilbit Offensive SecurityRıza Sabuncu @rizasabuncu Yiğit Can YILMAZ @yilmazcanyigit JeongOhKyea Tingting Yin Tsinghua UniversityJunoh Lee at Theori CVE-2022-43551 CVE-2022-43552 Aleksandar Nikolic Cisco TalosMikko Kenttälä ) @Turmio_ SensorFuJoshua Jones Ye Zhang @VAR10CK Baidu SecurityJubaer Alnazi TRS Group of Companiesryuzaki Murray Mike Pan ZhenPeng @Peterpan0927 STAR Labs SG PteArsenii Kostromin (0x3c3e) Félix Poulin-Bélanger David Pan Ogea Xinru Chi Pangu LabNed Williamson Google Project ZeroAdam Doupé ASU SEFCOMsqrtpwn an anonymous researcher Red CanaryMilan Tenk F FArthur Valiev FZweig Kunlun LabZhuowei Zhang developStorm Khiem Tran Mickey Jin @patch1t FFRI Security IncKoh M. Nakagawa FFRI Security IncMasahiro Kawada @kawakatz GMO Cybersecurity by IeraeJubaer Alnazi Jabin TRS Group Of Companies Alibaba GroupWenchao Li Alibaba GroupXiaolong Bai Alibaba GroupGuilherme Rambo Best Buddy Apps product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
Apple macOS | <13.3 | 13.3 |
Apple iOS and macOS | >=13.0<13.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2023-27939 is a vulnerability in ImageIO that allows an out-of-bounds read, which has been addressed with improved input validation.
CVE-2023-27939 affects macOS Ventura 13.3, where processing an image may result in disclosure of process memory.
CVE-2023-27939 has a severity rating of 5.5, which is considered medium.
To fix CVE-2023-27939, update your macOS Ventura to version 13.3 or later.
You can find more information about CVE-2023-27939 on the Apple support website: [link](https://support.apple.com/en-us/HT213670)