First published: Mon Jul 24 2023(Updated: )
PackageKit. An injection issue was addressed with improved input validation.
Credit: Michael Cowell product-security@apple.com product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
<13.5 | 13.5 | |
Apple macOS | >=13.0<13.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2023-38609 is a vulnerability in PackageKit that allows an app to bypass certain privacy preferences.
The severity of CVE-2023-38609 is high, with a CVSS score of 7.5.
CVE-2023-38609 affects macOS Ventura versions up to but excluding 13.5.
CVE-2023-38609 affects Apple iPadOS versions 13.0 to 13.4.1.
To fix CVE-2023-38609, update to macOS Ventura 13.5 or later.