First published: Mon Mar 27 2023(Updated: )
A buffer overflow issue was addressed with improved memory handling. This issue is fixed in macOS Ventura 13.3. Processing a maliciously crafted file may lead to unexpected app termination or arbitrary code execution
Credit: product-security@apple.com Yiğit Can YILMAZ @yilmazcanyigit Mickey Jin @patch1t Xin Huang @11iaxH CVE-2023-0049 CVE-2023-0051 CVE-2023-0054 CVE-2023-0288 CVE-2023-0433 CVE-2023-0512 Gertjan Franken imecKU Leuven hazbinhotel Trend Micro Zero Day InitiativeGeorgy Kucherin @kucher1n KasperskyLeonid Bezvershenko @bzvr_ KasperskyBoris Larin @oct0xor Kaspersky KasperskyValentin Pashkov Kasperskyan anonymous researcher Anonymous Trend Micro Zero Day InitiativeDohyun Lee @l33d0hyun SSD Labscrixer @pwning_me SSD LabsYe Zhang @VAR10CK Baidu SecurityJubaer Alnazi TRS Group of CompaniesCsaba Fitzl @theevilbit Offensive Securityjzhu Trend Micro Zero Day InitiativeMeysam Firouzi @R00tkitSMM Mbition Mercedesryuzaki Murray Mike Pan ZhenPeng @Peterpan0927 STAR Labs SG PteArsenii Kostromin (0x3c3e) Félix Poulin-Bélanger David Pan Ogea Xinru Chi Pangu LabNed Williamson Google Project ZeroAdam Doupé ASU SEFCOMsqrtpwn an anonymous researcher Red CanaryBrandon Dalton @partyD0lphin Red CanaryMilan Tenk F FArthur Valiev FZweig Kunlun LabJoshua Jones Zhuowei Zhang developStorm Khiem Tran Mickey Jin @patch1t FFRI Security IncKoh M. Nakagawa FFRI Security Inc Offensive SecurityMasahiro Kawada @kawakatz GMO Cybersecurity by IeraeJubaer Alnazi Jabin TRS Group Of Companies Alibaba GroupWenchao Li Alibaba GroupXiaolong Bai Alibaba GroupAdam M. Guilherme Rambo Best Buddy AppsABC Research s.r.o. Mohamed Ghannam @_simo36 Chan Shue Long Offensive SecurityRıza Sabuncu @rizasabuncu JeongOhKyea Tingting Yin Tsinghua UniversityJunoh Lee at Theori CVE-2022-43551 CVE-2022-43552 Aleksandar Nikolic Cisco TalosMikko Kenttälä ) @Turmio_ SensorFu
Affected Software | Affected Version | How to fix |
---|---|---|
Apple iOS and macOS | >=13.0<13.3 | |
macOS Ventura | <13.3 | 13.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2023-27957 is a buffer overflow issue in ImageIO that has been fixed in macOS Ventura 13.3 and may lead to unexpected app termination or arbitrary code execution when processing a maliciously crafted file.
CVE-2023-27957 has a severity score of 7.8 (high).
The affected software includes macOS Ventura 13.3 and Apple iPadOS versions between 13.0 and 13.3.
To fix CVE-2023-27957, update your macOS Ventura to version 13.3 or newer.
You can find more information about CVE-2023-27957 on the official Apple support page: https://support.apple.com/en-us/HT213670