Race condition in macOS - CVE-2023-23520
Published: February 27, 2023
Vulnerability identifier: #VU72585
CSH Severity: Low
CVSS v4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-23520
CWE-ID: CWE-362
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local application to gain access to sensitive information.
The vulnerability exists due to a race condition in Crash Reporter. A local application can exploit the race and read arbitrary files on the system with root privileges.
Affected software
macOS
watchOS
iPadOS
Apple iOS
tvOS
watchOS
iPadOS
Apple iOS
tvOS
How to mitigate CVE-2023-23520
Install updates from vendor's website.
macOS - update to 13.2 22D49
watchOS - update to 9.3 20S648
iPadOS - update to 16.3 20D47
Apple iOS - update to 16.3 20D47
tvOS - update to 16.3 20K650
watchOS - update to 9.3 20S648
iPadOS - update to 16.3 20D47
Apple iOS - update to 16.3 20D47
tvOS - update to 16.3 20K650