Buffer overflow in macOS - CVE-2023-42898
Published: December 11, 2023
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to a boundary error within the ImageIO component. A remote attacker can create a specially crafted image file, trick the victim into opening it, trigger memory corruption and execute arbitrary code on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
Affected software
watchOS
tvOS
iPadOS
Apple iOS
How to mitigate CVE-2023-42898
watchOS - update to 10.2
tvOS - update to 17.2
iPadOS - update to 17.2 21C62
Apple iOS - update to 17.2 21C62