First published: Wed Oct 25 2023(Updated: )
Automation. The issue was addressed with improved checks.
Credit: JZ product-security@apple.com Linus Henze Pinauten GmbHMickey Jin @patch1t Grzegorz Riegel Talal Haj Bakry Mysk IncTommy Mysk @mysk_co Mysk IncYiğit Can YILMAZ @yilmazcanyigit Kirin @Pwnrin SecuRingWojciech Regula SecuRing Computer ScienceCristian Dinca Computer ScienceRomania Bistrit Dahal CVE-2023-42946 이준성(Junsung Lee) Cross Republic이준성(Junsung Lee) Pedro Ribeiro @pedrib1337 Agile Information SecurityVitor Pedreira @0xvhp_ Agile Information SecurityAdam M. Csaba Fitzl @theevilbit Offensive SecurityMichael (Biscuit) Thomas - @social.lol @biscuit CVE-2023-42823 Mingxuan Yang @PPPF00L 360 Vulnerability Research Institute 360 Vulnerability Research Institutehappybabywu 360 Vulnerability Research InstituteGuang Gong 360 Vulnerability Research Institutean anonymous researcher inooo Alex Renda Claire Houston Kacper Kwapisz @KKKas_ Adis Alic Sam Lakmaker Ting Ding James Mancz Omar Shibli Lorenzo Cavallaro Harry Lewandowski Abhay Kailasia @abhay_kailasia Lakshmi Narain College Of Technology Bhopal IndiaPeter Nguyễn Vũ Hoàng @peternguyen14 STAR Labs SG PteTomi Tokics @tomitokics iTomsn0wZhipeng Huo @R3dF09 Tencent Security Xuanwu LabNoah Roskin-Frazee Pr
Affected Software | Affected Version | How to fix |
---|---|---|
Apple macOS | <14.1 | 14.1 |
tvOS | <17.1 | 17.1 |
Apple iOS, iPadOS, and watchOS | <10.1 | 10.1 |
macOS Ventura | <13.6.1 | 13.6.1 |
iPadOS | <16.7.2 | |
iPadOS | >=17.0<17.1 | |
iPhone OS | <16.7.2 | |
iPhone OS | >=17.0<17.1 | |
macOS | >=13.0<13.6.1 | |
macOS | =14.0 | |
tvOS | <17.1 | |
Apple iOS, iPadOS, and watchOS | <10.1 | |
Apple iOS and iPadOS | <17.1 | 17.1 |
Apple iOS, iPadOS, and macOS | <17.1 | 17.1 |
Apple iOS and iPadOS | <16.7.2 | 16.7.2 |
Apple iOS, iPadOS, and macOS | <16.7.2 | 16.7.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Appears in the following advisories)
(Found alongside the following vulnerabilities)
CVE-2023-42848 has been classified as a high severity vulnerability due to the potential for exploitation through malicious image processing.
To fix CVE-2023-42848, update your device to the latest versions of affected software, including macOS Sonoma 14.1, iOS 17.1, or watchOS 10.1.
CVE-2023-42848 affects multiple Apple products including iOS, iPadOS, tvOS, macOS Ventura, macOS Sonoma, and watchOS.
The new versions released to address CVE-2023-42848 are iOS and iPadOS 17.1, macOS Sonoma 14.1, watchOS 10.1, and macOS Ventura 13.6.1.
Yes, CVE-2023-42848 can affect older versions prior to the security patches, specifically those that have not been updated to the fixed releases.