Information disclosure in macOS - CVE-2023-23498
Published: January 23, 2023
Vulnerability details
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to an error in Mail Drafts implementation when forwarding emails. The quoted original message may be selected from the wrong email when forwarding an email from an Exchange account and lead to information disclosure.
Affected software
Apple iOS
iPadOS
How to mitigate CVE-2023-23498
Apple iOS - addressed in versions 15.7.3 19H307, 16.3 20D47
iPadOS - addressed in versions 15.7.3 19H307, 16.3 20D47