First published: Wed Oct 25 2023(Updated: )
The issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14.1, macOS Monterey 12.7.1, macOS Ventura 13.6.1. An app may be able to access user-sensitive data.
Credit: an anonymous researcher an anonymous researcher an anonymous researcher product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
Apple macOS Monterey | <12.7.1 | 12.7.1 |
Apple macOS | >=12.0<12.7.1 | |
Apple macOS | >=13.0<13.6.1 | |
Apple macOS | =14.0 | |
Apple macOS | <14.1 | 14.1 |
Apple macOS | <13.6.1 | 13.6.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2023-42858 has been classified with a severity level that indicates a significant potential risk to user-sensitive data.
To fix CVE-2023-42858, update your system to macOS Sonoma 14.1, macOS Monterey 12.7.1, or macOS Ventura 13.6.1.
CVE-2023-42858 affects devices running specific versions of macOS, including Monterey, Ventura, and Sonoma.
The impact of CVE-2023-42858 allows unauthorized access to user-sensitive information through the WindowServer.
CVE-2023-42858 was addressed in the updates released for macOS Sonoma 14.1, macOS Monterey 12.7.1, and macOS Ventura 13.6.1.