First published: Mon Mar 27 2023(Updated: )
Accessibility. A privacy issue was addressed with improved private data redaction for log entries.
Credit: Jubaer Alnazi Jabin TRS Group Of Companies Alibaba GroupWenchao Li Alibaba GroupXiaolong Bai Alibaba GroupZweig Kunlun LabMickey Jin @patch1t Joshua Jones Zhuowei Zhang Mickey Jin @patch1t FFRI Security IncKoh M. Nakagawa FFRI Security Inc Offensive SecurityCsaba Fitzl @theevilbit Offensive SecurityYiğit Can YILMAZ @yilmazcanyigit Adam M. Guilherme Rambo Best Buddy AppsCVE-2023-0433 CVE-2023-0512 sqrtpwn Arsenii Kostromin (0x3c3e) Pan ZhenPeng STAR Labs SG PteTingting Yin Tsinghua UniversityAleksandar Nikolic Cisco TalosYe Zhang @VAR10CK Baidu Securityan anonymous researcher Murray Mike Félix Poulin-Bélanger David Pan Ogea Xinru Chi Pangu LabNed Williamson Google Project ZeroMohamed GHANNAM @_simo36 Brandon Dalton @partyD0lphin Red CanaryRıza Sabuncu @rizasabuncu JeongOhKyea Xin Huang @11iaxH CVE-2023-0049 CVE-2023-0051 CVE-2023-0054 CVE-2023-0288 Gertjan Franken imecKU Leuven hazbinhotel Trend Micro Zero Day InitiativeGeorgy Kucherin @kucher1n KasperskyLeonid Bezvershenko @bzvr_ KasperskyBoris Larin @oct0xor Kaspersky KasperskyValentin Pashkov KasperskyAnonymous Trend Micro Zero Day InitiativeDohyun Lee @l33d0hyun SSD Labscrixer @pwning_me SSD LabsJubaer Alnazi TRS Group of Companiesjzhu Trend Micro Zero Day InitiativeMeysam Firouzi @R00tkitSMM Mbition Mercedesryuzaki Pan ZhenPeng @Peterpan0927 STAR Labs SG PteAdam Doupé ASU SEFCOMan anonymous researcher Red CanaryMilan Tenk F FArthur Valiev FdevelopStorm Khiem Tran Masahiro Kawada @kawakatz GMO Cybersecurity by IeraeABC Research s.r.o. Mohamed Ghannam @_simo36 Chan Shue Long Offensive SecurityJunoh Lee at Theori CVE-2022-43551 CVE-2022-43552 Mikko Kenttälä ) @Turmio_ SensorFuMohamed GHANNAM Itay Iellin General Motors Product Cyber SecurityJianjun Dai 360 Vulnerability Research InstituteGuang Gong 360 Vulnerability Research InstituteZechao Cai @Zech4o Zhejiang UniversityAbhay Kailasia @abhay_kailasia Lakshmi Narain College Of Technology BhopalAnton Spivak Hyeon Park @tree_segment Team ApplePIE TRS Group Of Companies product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
Apple iOS | <15.7.4 | 15.7.4 |
Apple iPadOS | <15.7.4 | 15.7.4 |
Apple iOS | <16.4 | 16.4 |
Apple iPadOS | <16.4 | 16.4 |
Apple macOS Monterey | <12.6.4 | 12.6.4 |
Apple macOS | <13.3 | 13.3 |
watchOS | <9.4 | 9.4 |
tvOS | <16.4 | 16.4 |
iPadOS | <15.7.4 | |
iPadOS | >=16.0<16.4 | |
Apple iPhone OS | <15.7.4 | |
Apple iPhone OS | >=16.0<16.4 | |
Apple macOS | >=12.0<12.6.4 | |
Apple macOS | >=13.0<13.3 | |
watchOS | <9.4 | |
iPadOS | <15.7.4 | |
iPadOS | >=16.0<16.4 | |
iPadOS | <16.4 | 16.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Appears in the following advisories)
(Found alongside the following vulnerabilities)
The vulnerability ID is CVE-2023-27963.
The severity of CVE-2023-27963 is high with a score of 7.5.
CVE-2023-27963 was addressed with additional permissions checks.
CVE-2023-27963 affects macOS Ventura 13.3, iOS 16.4 and iPadOS 16.4, iOS 15.7.4 and iPadOS 15.7.4, macOS Monterey 12.6.4, tvOS 16.4, and watchOS 9.4.
To fix CVE-2023-27963, update to the fixed versions: macOS Ventura 13.3, iOS 16.4 and iPadOS 16.4, iOS 15.7.4 and iPadOS 15.7.4, macOS Monterey 12.6.4, tvOS 16.4, or watchOS 9.4.