Improper Authentication in iPadOS and Apple iOS - CVE-2023-42973
Published: May 20, 2025
Vulnerability identifier: #VU109447
CSH Severity: Low
CVSS v4 BT: 0.4 [CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N/E:U/U:Clear]
CVE-ID: CVE-2023-42973
CWE-ID: CWE-287
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows an attacker to gain access to sensitive information.
The vulnerability exists due to an error in the user interface that allows accessing Safari private browser tabs without authentication. An attacker with physical access to the system can gain access to private browser tabs.
Affected software
iPadOS
Apple iOS
Apple iOS
How to mitigate CVE-2023-42973
Install updates from vendor's website.
iPadOS - update to 17.0
Apple iOS - addressed in versions 17.0 21A326, 17.0 21A327, 17.0 21A329, 17.0 21A331
Apple iOS - addressed in versions 17.0 21A326, 17.0 21A327, 17.0 21A329, 17.0 21A331