Integer overflow in macOS - CVE-2023-36495
Published: July 31, 2023
Vulnerability identifier: #VU78766
CSH Severity: Low
CVSS v4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-36495
CWE-ID: CWE-190
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local application to escalate privileges on the system.
The vulnerability exists due to integer overflow within the OS kernel. A local application can trigger an integer overflow and execute arbitrary code with kernel privileges.
Affected software
macOS
watchOS
iPadOS
Apple iOS
tvOS
watchOS
iPadOS
Apple iOS
tvOS
How to mitigate CVE-2023-36495
Install updates from vendor's website.
macOS - addressed in versions 13.5 22G74, 12.6.8 21G725
watchOS - update to 9.6 20U73
iPadOS - addressed in versions 15.7.8 19H364, 16.6
Apple iOS - addressed in versions 15.7.8 19H364, 16.6 20G75
tvOS - update to 16.6
watchOS - update to 9.6 20U73
iPadOS - addressed in versions 15.7.8 19H364, 16.6
Apple iOS - addressed in versions 15.7.8 19H364, 16.6 20G75
tvOS - update to 16.6