State Issues in iPadOS and Apple iOS - CVE-2023-42855
Published: February 19, 2024
Vulnerability identifier: #VU86583
CSH Severity: Low
CVSS v4 BT: 4 [CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear]
CVE-ID: CVE-2023-42855
CWE-ID: CWE-371
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows an attacker to compromise the affected device.
The vulnerability exists due to a state issue in Setup Assistant. An attacker with physical access to device can silently persist an Apple ID on an erased device.
Affected software
iPadOS
Apple iOS
Apple iOS
How to mitigate CVE-2023-42855
Install updates from vendor's website.
iPadOS - update to 17.1
Apple iOS - update to 17.1 21B74
Apple iOS - update to 17.1 21B74