Multiple vulnerabilities in Apple tvOS



Published: 2023-01-24 | Updated: 2023-02-02
Risk High
Patch available YES
Number of vulnerabilities 11
CVE-ID CVE-2023-23499
CVE-2023-23519
CVE-2023-23500
CVE-2023-23502
CVE-2023-23504
CVE-2023-23503
CVE-2023-23512
CVE-2023-23511
CVE-2023-23496
CVE-2023-23518
CVE-2023-23517
CWE-ID CWE-284
CWE-20
CWE-125
CWE-119
CWE-200
CWE-254
Exploitation vector Network
Public exploit N/A
Vulnerable software
Subscribe
tvOS
Operating systems & Components / Operating system

Vendor Apple Inc.

Security Bulletin

This security bulletin contains information about 11 vulnerabilities.

1) Improper access control

EUVDB-ID: #VU71432

Risk: Low

CVSSv3.1:

CVE-ID: CVE-2023-23499

CWE-ID: CWE-284 - Improper Access Control

Exploit availability: No

Description

The vulnerability allows a local application to gain access to sensitive information.

The vulnerability exists due to improper access restrictions in AppleMobileFileIntegrity. A local application can gain access to sensitive user information.

Mitigation

Install update from vendor's website.

Vulnerable software versions

tvOS: 16.0 20J373 - 16.2 20K362


CPE2.3 External links

http://support.apple.com/en-us/HT213601

Q & A

Can this vulnerability be exploited remotely?

Is there known malware, which exploits this vulnerability?

2) Input validation error

EUVDB-ID: #VU71444

Risk: Low

CVSSv3.1:

CVE-ID: CVE-2023-23519

CWE-ID: CWE-20 - Improper Input Validation

Exploit availability: No

Description

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to insufficient validation of user-supplied input in ImageIO. A remote attacker can trick the victim to open a specially crafted file and perform a denial of service (DoS) attack.

Mitigation

Install update from vendor's website.

Vulnerable software versions

tvOS: 16.0 20J373 - 16.2 20K362


CPE2.3 External links

http://support.apple.com/en-us/HT213601

Q & A

Can this vulnerability be exploited remotely?

Is there known malware, which exploits this vulnerability?

3) Out-of-bounds read

EUVDB-ID: #VU71445

Risk: Low

CVSSv3.1:

CVE-ID: CVE-2023-23500

CWE-ID: CWE-125 - Out-of-bounds read

Exploit availability: No

Description

The vulnerability allows a local application to gain access to potentially sensitive information.

The vulnerability exists due to a boundary condition within the OS kernel. A local application can trigger an out-of-bounds read error and read contents of memory on the system.

Mitigation

Install update from vendor's website.

Vulnerable software versions

tvOS: 16.0 20J373 - 16.2 20K362


CPE2.3 External links

http://support.apple.com/en-us/HT213601

Q & A

Can this vulnerability be exploited remotely?

Is there known malware, which exploits this vulnerability?

4) Out-of-bounds read

EUVDB-ID: #VU71442

Risk: Low

CVSSv3.1:

CVE-ID: CVE-2023-23502

CWE-ID: CWE-125 - Out-of-bounds read

Exploit availability: No

Description

The vulnerability allows a local application to gain access to potentially sensitive information.

The vulnerability exists due to a boundary condition within the OS kernel. A local application can trigger an out-of-bounds read error and read contents of memory on the system.

Mitigation

Install update from vendor's website.

Vulnerable software versions

tvOS: 16.0 20J373 - 16.2 20K362


CPE2.3 External links

http://support.apple.com/en-us/HT213601

Q & A

Can this vulnerability be exploited remotely?

Is there known malware, which exploits this vulnerability?

5) Buffer overflow

EUVDB-ID: #VU71441

Risk: Low

CVSSv3.1:

CVE-ID: CVE-2023-23504

CWE-ID: CWE-119 - Memory corruption

Exploit availability: No

Description

The vulnerability allows a local application to escalate privileges on the system.

The vulnerability exists due to a boundary error within the OS kernel. A local application can trigger memory corruption and execute arbitrary code with kernel privileges.


Mitigation

Install update from vendor's website.

Vulnerable software versions

tvOS: 16.0 20J373 - 16.2 20K362


CPE2.3 External links

http://support.apple.com/en-us/HT213601

Q & A

Can this vulnerability be exploited remotely?

Is there known malware, which exploits this vulnerability?

6) Information disclosure

EUVDB-ID: #VU71448

Risk: Low

CVSSv3.1:

CVE-ID: CVE-2023-23503

CWE-ID: CWE-200 - Information Exposure

Exploit availability: No

Description

The vulnerability allows a local application to gain access to potentially sensitive information.

The vulnerability exists due to a logic issue in Maps application. A local application can bypass Privacy preferences.

Mitigation

Install update from vendor's website.

Vulnerable software versions

tvOS: 16.0 20J373 - 16.2 20K362


CPE2.3 External links

http://support.apple.com/en-us/HT213601

Q & A

Can this vulnerability be exploited remotely?

Is there known malware, which exploits this vulnerability?

7) Input validation error

EUVDB-ID: #VU71450

Risk: Medium

CVSSv3.1:

CVE-ID: CVE-2023-23512

CWE-ID: CWE-20 - Improper Input Validation

Exploit availability: No

Description

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to insufficient handling of cache in Safari. A remote attacker can trick the victim into visiting a website and perform a denial of service (DoS) attack.

Mitigation

Install update from vendor's website.

Vulnerable software versions

tvOS: 16.0 20J373 - 16.2 20K362


CPE2.3 External links

http://support.apple.com/en-us/HT213601

Q & A

Can this vulnerability be exploited remotely?

Is there known malware, which exploits this vulnerability?

8) Security features bypass

EUVDB-ID: #VU71443

Risk: Low

CVSSv3.1:

CVE-ID: CVE-2023-23511

CWE-ID: CWE-254 - Security Features

Exploit availability: No

Description

The vulnerability allows a local application to bypass implemented security restrictions.

The vulnerability exists due to an error within the Weather application. A local application can bypass Privacy preferences.

Mitigation

Install update from vendor's website.

Vulnerable software versions

tvOS: 16.0 20J373 - 16.2 20K362


CPE2.3 External links

http://support.apple.com/en-us/HT213601

Q & A

Can this vulnerability be exploited remotely?

Is there known malware, which exploits this vulnerability?

9) Buffer overflow

EUVDB-ID: #VU71451

Risk: High

CVSSv3.1:

CVE-ID: CVE-2023-23496

CWE-ID: CWE-119 - Memory corruption

Exploit availability: No

Description

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to a boundary error when processing HTML content in WebKit. A remote attacker can create a specially crafted website, trick the victim into opening it, trigger memory corruption and execute arbitrary code on the target system.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.

Mitigation

Install update from vendor's website.

Vulnerable software versions

tvOS: 16.0 20J373 - 16.2 20K362


CPE2.3 External links

http://support.apple.com/en-us/HT213601

Q & A

Can this vulnerability be exploited remotely?

Is there known malware, which exploits this vulnerability?

10) Buffer overflow

EUVDB-ID: #VU71436

Risk: High

CVSSv3.1:

CVE-ID: CVE-2023-23518

CWE-ID: CWE-119 - Memory corruption

Exploit availability: No

Description

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to a boundary error when processing HTML content in WebKit. A remote attacker can create a specially crafted web page, trick the victim into opening it, trigger memory corruption and execute arbitrary code on the target system.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.

Mitigation

Install update from vendor's website.

Vulnerable software versions

tvOS: 16.0 20J373 - 16.2 20K362


CPE2.3 External links

http://support.apple.com/en-us/HT213601

Q & A

Can this vulnerability be exploited remotely?

Is there known malware, which exploits this vulnerability?

11) Buffer overflow

EUVDB-ID: #VU71437

Risk: High

CVSSv3.1:

CVE-ID: CVE-2023-23517

CWE-ID: CWE-119 - Memory corruption

Exploit availability: No

Description

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to a boundary error when processing HTML content in WebKit. A remote attacker can create a specially crafted web page, trick the victim into opening it, trigger memory corruption and execute arbitrary code on the target system.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.

Mitigation

Install update from vendor's website.

Vulnerable software versions

tvOS: 16.0 20J373 - 16.2 20K362


CPE2.3 External links

http://support.apple.com/en-us/HT213601

Q & A

Can this vulnerability be exploited remotely?

Is there known malware, which exploits this vulnerability?



###SIDEBAR###