CVE-2023-40398

HIGH

iPadOS < 16.4 - Sandbox Restriction Bypass

Title source: llm
STIX 2.1

Description

This issue was addressed with improved checks. This issue is fixed in macOS Monterey 12.6.4, macOS Big Sur 11.7.5, macOS Ventura 13.3, iOS 16.4 and iPadOS 16.4. A sandboxed process may be able to circumvent sandbox restrictions.

References (4)

Core 4
Core References
Release Notes, Vendor Advisory
https://support.apple.com/en-us/HT213670
Release Notes, Vendor Advisory
https://support.apple.com/en-us/HT213675
Release Notes, Vendor Advisory
https://support.apple.com/en-us/HT213676
Release Notes, Vendor Advisory
https://support.apple.com/en-us/HT213677

Scores

CVSS v3 8.8
EPSS 0.0015
EPSS Percentile 34.5%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

Status published
Products (3)
apple/ipados < 16.4
apple/iphone_os < 16.4
apple/macos < 11.7.5
Published Jul 29, 2024
Tracked Since Feb 18, 2026