CVE-2023-42936
https://notcve.org/view.php?id=CVE-2023-42936
28 Mar 2024 — This issue was addressed with improved redaction of sensitive information. This issue is fixed in macOS Monterey 12.7.2, macOS Ventura 13.6.3, iOS 17.2 and iPadOS 17.2, tvOS 17.2, watchOS 10.2, macOS Sonoma 14.2. An app may be able to access user-sensitive data. Este problema se solucionó mejorando la redacción de información confidencial. Este problema se solucionó en macOS Monterey 12.7.2, macOS Ventura 13.6.3, iOS 17.2 y iPadOS 17.2, tvOS 17.2, watchOS 10.2, macOS Sonoma 14.2. • https://support.apple.com/en-us/HT214035 •
CVE-2023-42950 – webkit: heap use-after-free may lead to arbitrary code execution
https://notcve.org/view.php?id=CVE-2023-42950
28 Mar 2024 — A use after free issue was addressed with improved memory management. This issue is fixed in Safari 17.2, iOS 17.2 and iPadOS 17.2, tvOS 17.2, watchOS 10.2, macOS Sonoma 14.2. Processing maliciously crafted web content may lead to arbitrary code execution. Se solucionó un problema de use after free con una gestión de memoria mejorada. Este problema se solucionó en Safari 17.2, iOS 17.2 y iPadOS 17.2, tvOS 17.2, watchOS 10.2, macOS Sonoma 14.2. • http://www.openwall.com/lists/oss-security/2024/03/26/1 • CWE-416: Use After Free •
CVE-2023-42947
https://notcve.org/view.php?id=CVE-2023-42947
28 Mar 2024 — A path handling issue was addressed with improved validation. This issue is fixed in macOS Monterey 12.7.2, macOS Ventura 13.6.3, iOS 17.2 and iPadOS 17.2, tvOS 17.2, watchOS 10.2, macOS Sonoma 14.2. An app may be able to break out of its sandbox. Se solucionó un problema de manejo de rutas con una validación mejorada. Este problema se solucionó en macOS Monterey 12.7.2, macOS Ventura 13.6.3, iOS 17.2 y iPadOS 17.2, tvOS 17.2, watchOS 10.2, macOS Sonoma 14.2. • https://support.apple.com/en-us/HT214035 •
CVE-2023-42896
https://notcve.org/view.php?id=CVE-2023-42896
28 Mar 2024 — An issue was addressed with improved handling of temporary files. This issue is fixed in macOS Monterey 12.7.2, macOS Ventura 13.6.3, iOS 17.2 and iPadOS 17.2, iOS 16.7.3 and iPadOS 16.7.3, macOS Sonoma 14.2. An app may be able to modify protected parts of the file system. Se solucionó un problema con el manejo mejorado de archivos temporales. Este problema se solucionó en macOS Monterey 12.7.2, macOS Ventura 13.6.3, iOS 17.2 y iPadOS 17.2, iOS 16.7.3 y iPadOS 16.7.3, macOS Sonoma 14.2. • https://support.apple.com/en-us/HT214034 • CWE-862: Missing Authorization •
CVE-2023-42893
https://notcve.org/view.php?id=CVE-2023-42893
28 Mar 2024 — A permissions issue was addressed by removing vulnerable code and adding additional checks. This issue is fixed in macOS Monterey 12.7.2, macOS Ventura 13.6.3, iOS 17.2 and iPadOS 17.2, iOS 16.7.3 and iPadOS 16.7.3, tvOS 17.2, watchOS 10.2, macOS Sonoma 14.2. An app may be able to access protected user data. Se solucionó un problema de permisos eliminando el código vulnerable y agregando comprobaciones adicionales. Este problema se solucionó en macOS Monterey 12.7.2, macOS Ventura 13.6.3, iOS 17.2 y iPadOS ... • http://seclists.org/fulldisclosure/2024/May/10 •
CVE-2023-42962
https://notcve.org/view.php?id=CVE-2023-42962
28 Mar 2024 — This issue was addressed with improved checks This issue is fixed in iOS 17.2 and iPadOS 17.2, iOS 16.7.3 and iPadOS 16.7.3. A remote attacker may be able to cause a denial-of-service. Este problema se solucionó con comprobaciones mejoradas. Este problema se solucionó en iOS 17.2 y iPadOS 17.2, iOS 16.7.3 y iPadOS 16.7.3. Un atacante remoto puede provocar una denegación de servicio. • https://support.apple.com/en-us/HT214034 •
CVE-2024-23273
https://notcve.org/view.php?id=CVE-2024-23273
08 Mar 2024 — This issue was addressed through improved state management. This issue is fixed in Safari 17.4, iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4. Private Browsing tabs may be accessed without authentication. Esta cuestión se abordó mediante una mejor gestión de estado. Este problema se solucionó en Safari 17.4, iOS 17.4 y iPadOS 17.4, macOS Sonoma 14.4. • http://seclists.org/fulldisclosure/2024/Mar/20 • CWE-295: Improper Certificate Validation •
CVE-2024-23270
https://notcve.org/view.php?id=CVE-2024-23270
08 Mar 2024 — The issue was addressed with improved memory handling. This issue is fixed in macOS Monterey 12.7.4, macOS Ventura 13.6.5, macOS Sonoma 14.4, iOS 17.4 and iPadOS 17.4, tvOS 17.4. An app may be able to execute arbitrary code with kernel privileges. El problema se solucionó mejorando el manejo de la memoria. Este problema se solucionó en macOS Monterey 12.7.4, macOS Ventura 13.6.5, macOS Sonoma 14.4, iOS 17.4 y iPadOS 17.4, tvOS 17.4. • http://seclists.org/fulldisclosure/2024/Mar/21 •
CVE-2024-23296 – Apple Multiple Products Memory Corruption Vulnerability
https://notcve.org/view.php?id=CVE-2024-23296
05 Mar 2024 — A memory corruption issue was addressed with improved validation. This issue is fixed in iOS 17.4 and iPadOS 17.4. An attacker with arbitrary kernel read and write capability may be able to bypass kernel memory protections. Apple is aware of a report that this issue may have been exploited. Se solucionó un problema de corrupción de memoria con una validación mejorada. • http://seclists.org/fulldisclosure/2024/Mar/18 • CWE-787: Out-of-bounds Write •
CVE-2024-23225 – Apple Multiple Products Memory Corruption Vulnerability
https://notcve.org/view.php?id=CVE-2024-23225
05 Mar 2024 — A memory corruption issue was addressed with improved validation. This issue is fixed in iOS 16.7.6 and iPadOS 16.7.6, iOS 17.4 and iPadOS 17.4. An attacker with arbitrary kernel read and write capability may be able to bypass kernel memory protections. Apple is aware of a report that this issue may have been exploited. Se solucionó un problema de corrupción de memoria con una validación mejorada. • http://seclists.org/fulldisclosure/2024/Mar/18 • CWE-787: Out-of-bounds Write •