Security features bypass in Apple iOS and iPadOS - CVE-2023-27943

 

Security features bypass in Apple iOS and iPadOS - CVE-2023-27943

Published: March 27, 2023


Vulnerability identifier: #VU74084
CSH Severity: Medium
CVSS v4: 7.5 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-27943
CWE-ID: CWE-254
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to bypass implemented security restrictions.

The vulnerability exists due to improperly implemented security checks within the LaunchServices component, which can result in files downloaded from the internet not having the quarantine flag applied. A remote attacker can trick the victim to download and execute malicious file and compromise the affected system.


Affected software

Apple iOS
iPadOS
macOS

How to mitigate CVE-2023-27943

Install updates from vendor's website.

Apple iOS - update to 16.4 20E247
iPadOS - update to 16.4 20E247
macOS - update to 13.3 22E252

External References

Related Security Bulletins