CVE-2023-42969

An app may be able to break out of its sandbox. This issue is fixed in iOS 17 and iPadOS 17, iOS 16.7 and iPadOS 16.7, macOS Sonoma 14, macOS Ventura 13.6, macOS Monterey 12.7. The issue was addressed with improved handling of caches.
References
Link Resource
https://support.apple.com/en-us/120328 Release Notes Vendor Advisory
https://support.apple.com/en-us/120329 Release Notes Vendor Advisory
https://support.apple.com/en-us/120337 Release Notes Vendor Advisory
https://support.apple.com/en-us/120949 Release Notes Vendor Advisory
https://support.apple.com/en-us/120950 Release Notes Vendor Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*

History

29 Apr 2025, 20:07

Type Values Removed Values Added
CPE cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*
Summary
  • (es) Una aplicación puede salir de la sandbox. Este problema se soluciona en iOS 17 y iPados 17, iOS 16.7 e iPados 16.7, Macos Sonoma 14, MacOS Ventura 13.6, MacOS Monterey 12.7. El problema se abordó con el manejo mejorado de los cachés.
First Time Apple macos
Apple
Apple iphone Os
Apple ipados
References () https://support.apple.com/en-us/120328 - () https://support.apple.com/en-us/120328 - Release Notes, Vendor Advisory
References () https://support.apple.com/en-us/120329 - () https://support.apple.com/en-us/120329 - Release Notes, Vendor Advisory
References () https://support.apple.com/en-us/120337 - () https://support.apple.com/en-us/120337 - Release Notes, Vendor Advisory
References () https://support.apple.com/en-us/120949 - () https://support.apple.com/en-us/120949 - Release Notes, Vendor Advisory
References () https://support.apple.com/en-us/120950 - () https://support.apple.com/en-us/120950 - Release Notes, Vendor Advisory

11 Apr 2025, 16:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 3.3
CWE CWE-284

11 Apr 2025, 15:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-04-11 15:15

Updated : 2025-04-29 20:07


NVD link : CVE-2023-42969

Mitre link : CVE-2023-42969

CVE.ORG link : CVE-2023-42969


JSON object : View

Products Affected

apple

  • ipados
  • iphone_os
  • macos
CWE
CWE-284

Improper Access Control