CVE-2023-42897

MEDIUM

iPadOS 17.0-17.1 - Unauthenticated Sensitive Data Exposure via Siri

Title source: llm
STIX 2.1

Description

The issue was addressed with improved checks. This issue is fixed in iOS 17.2 and iPadOS 17.2. An attacker with physical access may be able to use Siri to access sensitive user data.

References (3)

Core 3
Core References
Release Notes, Vendor Advisory
https://support.apple.com/en-us/HT214035

Scores

CVSS v3 4.6
EPSS 0.0007
EPSS Percentile 21.2%
Attack Vector PHYSICAL
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

Status published
Products (2)
apple/ipados 17.0 - 17.2
apple/iphone_os 17.0 - 17.2
Published Dec 12, 2023
Tracked Since Feb 18, 2026