Buffer overflow in macOS - CVE-2023-38610
Published: December 26, 2023
Vulnerability identifier: #VU84767
CSH Severity: High
CVSS v4 BT: 6.3 [CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Amber]
CVE-ID: CVE-2023-38610
CWE-ID: CWE-119
Exploitation vector: Adjecent network
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to a boundary error within the Wi-Fi subsystem. A remote attacker can send specially crafted data to the system, trigger memory corruption and execute arbitrary code with kernel privileges.
Affected software
macOS
Apple iOS
iPadOS
Apple iOS
iPadOS
How to mitigate CVE-2023-38610
Install updates from vendor's website.
macOS - update to 14.0 23A344
Apple iOS - update to 17.0 21A327
iPadOS - update to 17.0
Apple iOS - update to 17.0 21A327
iPadOS - update to 17.0