CVE-2023-23526
https://notcve.org/view.php?id=CVE-2023-23526
This was addressed with additional checks by Gatekeeper on files downloaded from an iCloud shared-by-me folder. This issue is fixed in macOS Ventura 13.3, iOS 16.4 and iPadOS 16.4. A file from an iCloud shared-by-me folder may be able to bypass Gatekeeper. • https://support.apple.com/en-us/HT213670 https://support.apple.com/en-us/HT213676 •
CVE-2023-23532
https://notcve.org/view.php?id=CVE-2023-23532
This issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.3, iOS 16.4 and iPadOS 16.4, iOS 15.7.6 and iPadOS 15.7.6. An app may be able to break out of its sandbox. • https://support.apple.com/en-us/HT213670 https://support.apple.com/en-us/HT213676 https://support.apple.com/en-us/HT213765 •
CVE-2022-42838
https://notcve.org/view.php?id=CVE-2022-42838
An issue with app access to camera data was addressed with improved logic. This issue is fixed in macOS Ventura 13. A camera extension may be able to continue receiving video after the app which activated was closed. • https://support.apple.com/en-us/HT213488 • CWE-672: Operation on a Resource after Expiration or Release •
CVE-2022-46713
https://notcve.org/view.php?id=CVE-2022-46713
A race condition was addressed with additional validation. This issue is fixed in macOS Ventura 13, macOS Monterey 12.6.1, macOS Big Sur 11.7.1. An app may be able to modify protected parts of the file system. • https://support.apple.com/en-us/HT213488 https://support.apple.com/en-us/HT213493 https://support.apple.com/en-us/HT213494 • CWE-362: Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') •
CVE-2020-9846
https://notcve.org/view.php?id=CVE-2020-9846
A logic issue was addressed with improved state management. This issue is fixed in macOS Monterey 12.0.1. A malicious application may be able to access local users' Apple IDs. • https://support.apple.com/en-us/HT212869 •