First published: Wed Oct 25 2023(Updated: )
A logic issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14.1, iOS 17.1 and iPadOS 17.1. An attacker may be able to access passkeys without authentication.
Credit: an anonymous researcher an anonymous researcher product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
Apple iOS | <17.1 | 17.1 |
Apple iPadOS | <17.1 | 17.1 |
Apple macOS Sonoma | <14.1 | 14.1 |
Apple iPadOS | >=17.0<17.1 | |
Apple iPhone OS | >=17.0<17.1 | |
Apple macOS | >=14.0<14.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2023-42847 is a logic issue in passkeys that allows an attacker to access passkeys without authentication.
CVE-2023-42847 affects macOS Sonoma version up to and excluding 14.1.
CVE-2023-42847 affects iOS version up to and excluding 17.1.
CVE-2023-42847 affects iPadOS version up to and excluding 17.1.
To fix CVE-2023-42847, update your operating system to macOS Sonoma 14.1, iOS 17.1, or iPadOS 17.1.