Improper Authentication in iPadOS and Apple iOS - CVE-2023-42973

 

Improper Authentication in iPadOS and Apple iOS - CVE-2023-42973

Published: May 20, 2025


Vulnerability identifier: #VU109447
CSH Severity: Low
CVSS v4 BT: 0.4 [CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N/E:U/U:Clear]
CVE-ID: CVE-2023-42973
CWE-ID: CWE-287
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows an attacker to gain access to sensitive information.

The vulnerability exists due to an error in the user interface that allows accessing Safari private browser tabs without authentication. An attacker with physical access to the system can gain access to private browser tabs.


Affected software

iPadOS
Apple iOS

How to mitigate CVE-2023-42973

Install updates from vendor's website.

iPadOS - update to 17.0
Apple iOS - addressed in versions 17.0 21A326, 17.0 21A327, 17.0 21A329, 17.0 21A331

External References

Related Security Bulletins