First published: Wed Oct 25 2023(Updated: )
A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in macOS Monterey 12.7.1. An app with root privileges may be able to access private information.
Credit: Csaba Fitzl @theevilbit Offensive Security product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
Apple macOS Monterey | <12.7.1 | 12.7.1 |
Apple macOS | >=12.0.0<12.7.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2023-40425 is a vulnerability in macOS Monterey 12.7.1 that allows an app with root privileges to access private information due to a privacy issue.
CVE-2023-40425 affects macOS Monterey 12.7.1 by allowing an app with root privileges to access private information.
The fix for CVE-2023-40425 is to update to macOS Monterey 12.7.1.
You can find more information about CVE-2023-40425 on the Apple support page and the Full Disclosure mailing list.