CVE-2023-40401

HIGH

macOS 13.0-13.6.1 - Unauthenticated Passkey Access

Title source: llm
STIX 2.1

Description

The issue was addressed with additional permissions checks. This issue is fixed in macOS Ventura 13.6.1. An attacker may be able to access passkeys without authentication.

References (6)

Core 6
Core References
Mailing List, Third Party Advisory
http://seclists.org/fulldisclosure/2023/Oct/26
Release Notes, Vendor Advisory
https://support.apple.com/en-us/HT213985
Release Notes, Vendor Advisory
https://support.apple.com/kb/HT213985

Scores

CVSS v3 7.5
EPSS 0.0012
EPSS Percentile 30.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-306
Status published
Products (1)
apple/macos 13.0 - 13.6.1
Published Oct 25, 2023
Tracked Since Feb 18, 2026