State Issues in iPadOS and Apple iOS - CVE-2023-42855

 

State Issues in iPadOS and Apple iOS - CVE-2023-42855

Published: February 19, 2024


Vulnerability identifier: #VU86583
CSH Severity: Low
CVSS v4 BT: 4 [CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear]
CVE-ID: CVE-2023-42855
CWE-ID: CWE-371
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows an attacker to compromise the affected device.

The vulnerability exists due to a state issue in Setup Assistant. An attacker with physical access to device can silently persist an Apple ID on an erased device.


Affected software

iPadOS
Apple iOS

How to mitigate CVE-2023-42855

Install updates from vendor's website.

iPadOS - update to 17.1
Apple iOS - update to 17.1 21B74

External References

Related Security Bulletins