CVE-2023-32393 – webkitgtk: arbitrary code execution
https://notcve.org/view.php?id=CVE-2023-32393
The issue was addressed with improved memory handling. This issue is fixed in watchOS 9.3, tvOS 16.3, macOS Ventura 13.2, iOS 16.3 and iPadOS 16.3. Processing web content may lead to arbitrary code execution. A flaw was found in WebKitGTK. This issue occurs when processing malicious web content, which may lead to arbitrary code execution. • https://security.gentoo.org/glsa/202401-04 https://support.apple.com/en-us/HT213599 https://support.apple.com/en-us/HT213601 https://support.apple.com/en-us/HT213605 https://support.apple.com/en-us/HT213606 https://access.redhat.com/security/cve/CVE-2023-32393 https://bugzilla.redhat.com/show_bug.cgi?id=2224608 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •
CVE-2023-38602
https://notcve.org/view.php?id=CVE-2023-38602
A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Monterey 12.6.8, macOS Ventura 13.5, macOS Big Sur 11.7.9. An app may be able to modify protected parts of the file system. • https://support.apple.com/en-us/HT213843 https://support.apple.com/en-us/HT213844 https://support.apple.com/en-us/HT213845 •
CVE-2023-38421 – Apple macOS Hydra Parsing Out-Of-Bounds Read Information Disclosure Vulnerability
https://notcve.org/view.php?id=CVE-2023-38421
The issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.5, macOS Monterey 12.6.8. Processing a 3D model may result in disclosure of process memory. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Apple macOS. Interaction with the Hydra library is required to exploit this vulnerability but attack vectors may vary depending on the implementation. The specific flaw exists within the Hydra framework. • https://support.apple.com/en-us/HT213843 https://support.apple.com/en-us/HT213844 •
CVE-2023-38564
https://notcve.org/view.php?id=CVE-2023-38564
The issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.5. An app may be able to modify protected parts of the file system. • https://support.apple.com/en-us/HT213843 •
CVE-2023-36862
https://notcve.org/view.php?id=CVE-2023-36862
A downgrade issue affecting Intel-based Mac computers was addressed with additional code-signing restrictions. This issue is fixed in macOS Ventura 13.5. An app may be able to determine a user’s current location. • https://support.apple.com/en-us/HT213843 •