Security features bypass in Apple iOS and iPadOS - CVE-2023-27943
Published: March 27, 2023
Vulnerability details
The vulnerability allows a remote attacker to bypass implemented security restrictions.
The vulnerability exists due to improperly implemented security checks within the LaunchServices component, which can result in files downloaded from the internet not having the quarantine flag applied. A remote attacker can trick the victim to download and execute malicious file and compromise the affected system.
Affected software
iPadOS
macOS
How to mitigate CVE-2023-27943
iPadOS - update to 16.4 20E247
macOS - update to 13.3 22E252