First published: Wed Oct 25 2023(Updated: )
An authentication issue was addressed with improved state management. This issue is fixed in macOS Ventura 13.6.4. A local attacker may be able to view the previous logged in user’s desktop from the fast user switching screen.
Credit: ASentientBot product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
Apple macOS | >=13.0<13.6.4 | |
Apple macOS | >=14.0<14.1 | |
Apple macOS | <14.1 | 14.1 |
Apple macOS | <13.6.4 | 13.6.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2023-42935 is considered a moderate severity vulnerability due to potential unauthorized access to user sessions.
To fix CVE-2023-42935, upgrade to macOS Ventura 13.6.4 or macOS Sonoma 14.1.
Users of macOS versions prior to 13.6.4 and between 14.0 and 14.1 are affected by CVE-2023-42935.
CVE-2023-42935 involves a local attack allowing visibility of the previous user's desktop during fast user switching.
CVE-2023-42935 was fixed in macOS Ventura 13.6.4 and macOS Sonoma 14.1.