First published: Wed Oct 25 2023(Updated: )
A logic issue was addressed with improved state management. This issue is fixed in macOS Sonoma 14.1. An attacker with knowledge of a standard user's credentials can unlock another standard user's locked screen on the same Mac.
Credit: product-security@apple.com an anonymous researcher Concentrix凯 王 ConcentrixSteven Maser ConcentrixMatthew McLean ConcentrixBrandon Chesser ConcentrixCPU IT inc Concentrix ConcentrixAvalon IT Team ConcentrixJon Crain Concentrix凯 王 ConcentrixBrandon Chesser & CPU IT inc ConcentrixMatthew McLean ConcentrixSteven Maser Concentrix Concentrixthe Avalon IT Team Concentrix
Affected Software | Affected Version | How to fix |
---|---|---|
Apple macOS | >=14.0<14.1 | |
Apple macOS Sonoma | <14.1 | 14.1 |
Apple macOS Ventura | <13.6.7 | 13.6.7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2023-42861 is a logic issue in the Login Window of macOS Sonoma 14.1, which allows an attacker to unlock another user's locked screen on the same Mac.
An attacker with knowledge of a standard user's credentials can unlock another standard user's locked screen on the same Mac.
The severity of CVE-2023-42861 is moderate.
To fix CVE-2023-42861, update your macOS to Sonoma 14.1 or later.
For more information about CVE-2023-42861, you can refer to the following resources: [Apple Support](https://support.apple.com/en-us/HT213984), [Full Disclosure Mailing List](http://seclists.org/fulldisclosure/2023/Oct/24), [Apple Security Updates](https://support.apple.com/kb/HT213984).