First published: Wed Oct 25 2023(Updated: )
Foundation. This issue was addressed with improved handling of symlinks.
Credit: Ron Masas BreakPointRon Masas BreakPointRon Masas BreakPoint product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
<12.7.1 | 12.7.1 | |
Apple macOS Sonoma | <14.1 | 14.1 |
Apple macOS Ventura | <13.6.1 | 13.6.1 |
Apple macOS | >=12.0.0<12.7.1 | |
Apple macOS | >=13.0<13.6.1 | |
Apple macOS | >=14.0<14.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2023-42844 is a vulnerability that allows a website to access sensitive user data when resolving symlinks.
macOS Sonoma 14.1, macOS Monterey 12.7.1, and macOS Ventura 13.6.1 are affected by CVE-2023-42844.
CVE-2023-42844 was fixed with improved handling of symlinks in macOS Sonoma 14.1, macOS Monterey 12.7.1, and macOS Ventura 13.6.1.
To protect yourself from CVE-2023-42844, ensure that you have installed the latest updates for macOS Sonoma, Monterey, or Ventura.
You can find more information about CVE-2023-42844 on the Apple support page: [link1], [link2], [link3].