This issue was addressed with improved validation of symlinks. This issue is fixed in macOS Ventura 13.6, tvOS 17, macOS Monterey 12.7, watchOS 10, iOS 17 and iPadOS 17, macOS Sonoma 14. An app may be able to read arbitrary files.
Metrics
Affected Vendors & Products
References
History
Tue, 24 Sep 2024 15:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
MITRE
Status: PUBLISHED
Assigner: apple
Published: 2023-09-26T20:14:32.105Z
Updated: 2024-09-24T14:48:30.306Z
Reserved: 2023-09-14T19:03:36.103Z
Link: CVE-2023-41968
Vulnrichment
Updated: 2024-08-02T19:09:49.401Z
NVD
Status : Modified
Published: 2023-09-27T15:19:31.653
Modified: 2024-11-21T08:22:00.810
Link: CVE-2023-41968
Redhat
No data.