Permissions, Privileges, and Access Controls in Apple iOS and iPadOS - CVE-2023-27963
Published: March 27, 2023
Vulnerability identifier: #VU74093
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-27963
CWE-ID: CWE-264
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to gain access to sensitive information.
The vulnerability exists due to improper permissions checks in Shortcuts. A shortcut may be able to use sensitive data with certain actions without prompting the user.
Affected software
Apple iOS
iPadOS
watchOS
macOS
tvOS
iPadOS
watchOS
macOS
tvOS
How to mitigate CVE-2023-27963
Install updates from vendor's website.
Apple iOS - addressed in versions 16.4 20E247, 15.7.4 19H321
iPadOS - addressed in versions 16.4 20E247, 15.7.4 19H321
watchOS - update to 9.4 20T253
macOS - addressed in versions 12.6.4 21G526, 13.3 22E252
tvOS - update to 16.4 20L497
iPadOS - addressed in versions 16.4 20E247, 15.7.4 19H321
watchOS - update to 9.4 20T253
macOS - addressed in versions 12.6.4 21G526, 13.3 22E252
tvOS - update to 16.4 20L497