First published: Mon Jul 24 2023(Updated: )
PackageKit. A logic issue was addressed with improved restrictions.
Credit: Mickey Jin @patch1t product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
Apple macOS | <11.7.9 | 11.7.9 |
macOS | <12.6.8 | 12.6.8 |
macOS Ventura | <13.5 | 13.5 |
macOS | >=11.0<11.7.9 | |
macOS | >=12.0<12.6.8 | |
macOS | >=13.0<13.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2023-38259 is a logic issue in PackageKit that has been addressed with improved restrictions.
Due to CVE-2023-38259, an app may be able to access user-sensitive data.
macOS versions 11.0 to 11.7.9, 12.0 to 12.6.8, and 13.0 to 13.5 are affected by CVE-2023-38259.
CVE-2023-38259 has a severity value of 5.5, which is considered medium.
To fix CVE-2023-38259, update macOS to the fixed versions: Monterey 12.6.8, Ventura 13.5, or Big Sur 11.7.9.