First published: Mon Jul 24 2023(Updated: )
PackageKit. A permissions issue was addressed with additional restrictions.
Credit: Arsenii Kostromin (0x3c3e) Arsenii Kostromin (0x3c3e) Arsenii Kostromin (0x3c3e) product-security@apple.com product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
<13.5 | 13.5 | |
<12.6.8 | 12.6.8 | |
Apple macOS Big Sur | <11.7.9 | 11.7.9 |
Apple macOS | >=13.0<13.5 | |
Apple macOS | >=12.0<12.6.8 | |
Apple macOS | <11.7.9 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2023-38602 is a vulnerability in PackageKit that allows an app to modify protected parts of the file system.
CVE-2023-38602 has a severity rating of 5.5 (medium).
CVE-2023-38602 affects macOS versions up to and including Monterey 12.6.8, Ventura 13.5, and Big Sur 11.7.9.
To fix CVE-2023-38602, update your macOS to the fixed versions: Monterey 12.6.8, Ventura 13.5, or Big Sur 11.7.9.
You can find more information about CVE-2023-38602 on the Apple Support website.