Inclusion of Sensitive Information in Log Files in iPadOS and Apple iOS - CVE-2023-42823
Published: February 19, 2024
Vulnerability identifier: #VU86565
CSH Severity: Low
CVSS v4 BT: 1.1 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear]
CVE-ID: CVE-2023-42823
CWE-ID: CWE-532
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local application to gain access to sensitive information.
The vulnerability exists due to the Core Recents component stores sensitive information into log files. A local application can read the log files and gain access to sensitive user data.
Affected software
iPadOS
Apple iOS
tvOS
watchOS
macOS
Apple iOS
tvOS
watchOS
macOS
How to mitigate CVE-2023-42823
Install updates from vendor's website.
iPadOS - addressed in versions 16.7.2, 17.1
Apple iOS - addressed in versions 16.7.2 20H115, 17.1 21B74
tvOS - update to 17.1
watchOS - update to 10.1
macOS - addressed in versions 12.7.1 21G920, 13.6.1 22G313, 14.1 23B74
Apple iOS - addressed in versions 16.7.2 20H115, 17.1 21B74
tvOS - update to 17.1
watchOS - update to 10.1
macOS - addressed in versions 12.7.1 21G920, 13.6.1 22G313, 14.1 23B74
External References
Related Security Bulletins
- Multiple vulnerabilities in Apple iOS 16 and iPadOS 16
- Multiple vulnerabilities in Apple iOS 17 and iPadOS 17
- Multiple vulnerabilities in Apple macOS Monterey
- Multiple vulnerabilities in Apple watchOS 10
- Multiple vulnerabilities in Apple tvOS 17
- Multiple vulnerabilities in Apple macOS Ventura
- Multiple vulnerabilities in Apple macOS Sonoma