First published: Mon Jul 24 2023(Updated: )
PackageKit. A logic issue was addressed with improved restrictions.
Credit: Mickey Jin @patch1t Mickey Jin @patch1t Mickey Jin @patch1t product-security@apple.com product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
<13.5 | 13.5 | |
<12.6.8 | 12.6.8 | |
Apple macOS Big Sur | <11.7.9 | 11.7.9 |
Apple macOS | >=13.0<13.5 | |
Apple macOS | >=12.0<12.6.8 | |
Apple macOS | >=11.0<11.7.9 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2023-38259 is a logic issue in PackageKit that has been addressed with improved restrictions.
Due to CVE-2023-38259, an app may be able to access user-sensitive data.
macOS versions 11.0 to 11.7.9, 12.0 to 12.6.8, and 13.0 to 13.5 are affected by CVE-2023-38259.
CVE-2023-38259 has a severity value of 5.5, which is considered medium.
To fix CVE-2023-38259, update macOS to the fixed versions: Monterey 12.6.8, Ventura 13.5, or Big Sur 11.7.9.