CVE-2023-27960: High severity apple garageband vulnerability
Published Mar 7, 2023
·Updated
GarageBand. This issue was addressed by removing the vulnerable code.
Other sources
This issue was addressed by removing the vulnerable code. This issue is fixed in GarageBand for macOS 10.4.8. An app may be able to gain elevated privileges during the installation of GarageBand
Credit
Mickey Jin@@patch1t
Affected Software
3 affected componentsFixes available
Apple GarageB
Apple for macOS<10.4.8
10.4.8
Apple iOS and macOS>=10.0<10.4.8
Event History
May 8, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionWeakness
Data Sourced
08:15 PM
Description
Data Sourced
via NVD·08:15 PM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the vulnerability ID of this issue?
The vulnerability ID of this issue is CVE-2023-27960.
2
How was this vulnerability fixed?
This vulnerability was fixed by removing the vulnerable code in GarageBand for macOS 10.4.8.
3
What is the severity of CVE-2023-27960?
The severity of CVE-2023-27960 is high, with a CVSS score of 7.8.
4
What can an app do with this vulnerability?
An app may be able to gain elevated privileges during the installation of GarageBand.
5
Where can I find more information about this vulnerability?
You can find more information about this vulnerability on the following Apple support page: [link](https://support.apple.com/en-us/HT213650).