Improper access control in macOS - CVE-2023-32438
Published: September 11, 2023
Vulnerability identifier: #VU80588
CSH Severity: Low
CVSS v4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-32438
CWE-ID: CWE-284
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local application to gain unauthorized access to otherwise restricted functionality.
The vulnerability exists due to improper access restrictions in AppleMobileFileIntegrity. A local application can bypass implemented security restrictions and gain unauthorized access to the application.
Affected software
macOS
watchOS
iPadOS
Apple iOS
tvOS
watchOS
iPadOS
Apple iOS
tvOS
How to mitigate CVE-2023-32438
Install updates from vendor's website.
macOS - update to 13.2 22D49
watchOS - update to 9.3 20S648
iPadOS - update to 16.3 20D47
Apple iOS - update to 16.3 20D47
tvOS - update to 16.3 20K650
watchOS - update to 9.3 20S648
iPadOS - update to 16.3 20D47
Apple iOS - update to 16.3 20D47
tvOS - update to 16.3 20K650