CVE-2023-42974

HIGH

Apple macOS and iOS Kernel - App Code Execution with Kernel Privileges

Title source: manual
STIX 2.1

Description

A race condition was addressed with improved state handling. This issue is fixed in macOS Monterey 12.7.2, macOS Ventura 13.6.3, iOS 17.2 and iPadOS 17.2, iOS 16.7.3 and iPadOS 16.7.3, macOS Sonoma 14.2. An app may be able to execute arbitrary code with kernel privileges.

Scores

CVSS v3 7.0
EPSS 0.0007
EPSS Percentile 21.6%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-362
Status published
Products (4)
apple/ipad_os < 16.7.3
apple/ipados 17.0 - 17.2
apple/iphone_os < 16.7.3
apple/macos 12.0 - 12.7.2
Published Mar 28, 2024
Tracked Since Feb 18, 2026