Out-of-bounds read in macOS - CVE-2023-32368
Published: May 18, 2023
Vulnerability details
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to a boundary condition when processing 3D models in Model I/O. A remote attacker can create a specially crafted file, trick the victim into opening it, trigger an out-of-bounds read error and read contents of memory on the system.
Affected software
watchOS
iPadOS
Apple iOS
tvOS
How to mitigate CVE-2023-32368
watchOS - update to 9.5 20T562
iPadOS - update to 16.5 20F66
Apple iOS - update to 16.5 20F66
tvOS - update to 16.5 20L562