CVE-2023-23543
https://notcve.org/view.php?id=CVE-2023-23543
The issue was addressed with additional restrictions on the observability of app states. This issue is fixed in macOS Ventura 13.3, iOS 15.7.4 and iPadOS 15.7.4, iOS 16.4 and iPadOS 16.4, watchOS 9.4. A sandboxed app may be able to determine which app is currently using the camera. • https://support.apple.com/en-us/HT213670 https://support.apple.com/en-us/HT213673 https://support.apple.com/en-us/HT213676 https://support.apple.com/en-us/HT213678 •
CVE-2023-23532
https://notcve.org/view.php?id=CVE-2023-23532
This issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.3, iOS 16.4 and iPadOS 16.4, iOS 15.7.6 and iPadOS 15.7.6. An app may be able to break out of its sandbox. • https://support.apple.com/en-us/HT213670 https://support.apple.com/en-us/HT213676 https://support.apple.com/en-us/HT213765 •
CVE-2022-42838
https://notcve.org/view.php?id=CVE-2022-42838
An issue with app access to camera data was addressed with improved logic. This issue is fixed in macOS Ventura 13. A camera extension may be able to continue receiving video after the app which activated was closed. • https://support.apple.com/en-us/HT213488 • CWE-672: Operation on a Resource after Expiration or Release •
CVE-2022-22668
https://notcve.org/view.php?id=CVE-2022-22668
A logic issue was addressed with improved restrictions. This issue is fixed in iOS 15.4 and iPadOS 15.4, macOS Monterey 12.3. A malicious application may be able to leak sensitive user information. • https://support.apple.com/en-us/HT213182 https://support.apple.com/en-us/HT213183 •
CVE-2022-46713
https://notcve.org/view.php?id=CVE-2022-46713
A race condition was addressed with additional validation. This issue is fixed in macOS Ventura 13, macOS Monterey 12.6.1, macOS Big Sur 11.7.1. An app may be able to modify protected parts of the file system. • https://support.apple.com/en-us/HT213488 https://support.apple.com/en-us/HT213493 https://support.apple.com/en-us/HT213494 • CWE-362: Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') •