First published: Mon Sep 18 2023(Updated: )
Passkeys. The issue was addressed with additional permissions checks.
Credit: an anonymous researcher weize she weize she an anonymous researcher weize she an anonymous researcher an anonymous researcher weize she product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
Apple macOS | >=13.0<13.6.1 | |
Apple iOS | <16.7 | 16.7 |
Apple iPadOS | <16.7 | 16.7 |
Apple macOS Ventura | <13.6.1 | 13.6.1 |
<14 | 14 | |
Apple iOS | <17 | 17 |
Apple iPadOS | <17 | 17 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
The vulnerability ID for this issue is CVE-2023-40401.
The impact of vulnerability CVE-2023-40401 is that an attacker may be able to access passkeys without authentication.
CVE-2023-40401 affects macOS Ventura versions up to but excluding 13.6.1.
Vulnerability CVE-2023-40401 was addressed with additional permissions checks.
You can find more information about vulnerability CVE-2023-40401 at the following references: [Support Article](https://support.apple.com/en-us/HT213985), [Security Mailing List](http://seclists.org/fulldisclosure/2023/Oct/26), [Apple Knowledge Base Article](https://support.apple.com/kb/HT213985).