CERT-In Advisory
CIAD-2023-0047
Multiple Vulnerabilities in Apple Products
Original Issue Date: December 15, 2023
Severity Rating: High
Software Affected
- Apple iOS versions prior to 17.2 and iPadOS versions prior to 17.2
- Apple iOS versions prior to 16.7.3 and iPadOS versions prior to 16.7.3
- Apple macOS Sonoma versions prior to 14.2
- Apple macOS Ventura versions prior to 13.6.3
- Apple macOS Monterey versions prior to 12.7.2
- Apple tvOS versions prior to 17.2
- Apple watchOS versions prior to 10.2
- Apple Safari versions prior to 17.2
Overview
Multiple vulnerabilities have been reported in Apple products which could allow an attacker to access sensitive information, execute arbitrary code, bypass security restrictions, cause denial of service (DoS) conditions, bypass authentication, gain elevated privileges and perform spoofing attacks on the targeted system.
Description
Multiple vulnerabilities have been reported in Apple products:
Note: CVE-2023-42916 and CVE-2023-42917 are being exploited in the wild. Users are advised to update to the latest OS patches.
Solution
Apply appropriate software updates as mentioned in the Apple Security updates:
https://support.apple.com/en-us/HT214034
https://support.apple.com/en-us/HT214035
https://support.apple.com/en-us/HT214036
https://support.apple.com/en-us/HT214037
https://support.apple.com/en-us/HT214038
https://support.apple.com/en-us/HT214039
https://support.apple.com/en-us/HT214040
https://support.apple.com/en-us/HT214041
Vendor Information
Apple
https://support.apple.com/en-us/HT214034
https://support.apple.com/en-us/HT214035
https://support.apple.com/en-us/HT214036
https://support.apple.com/en-us/HT214037
https://support.apple.com/en-us/HT214038
https://support.apple.com/en-us/HT214039
https://support.apple.com/en-us/HT214040
https://support.apple.com/en-us/HT214041
CVE Name
CVE-2023-42919
CVE-2023-42884
CVE-2023-458666
CVE-2023-42927
CVE-2023-42922
CVE-2023-42898
CVE-2023-42899
CVE-2023-42914
CVE-2023-42923
CVE-2023-42897
CVE-2023-42890
CVE-2023-42883
CVE-2023-42917
CVE-2023-42916
CVE-2023-42874
CVE-2023-42894
CVE-2023-42901
CVE-2023-42902
CVE-2023-42903
CVE-2023-42904
CVE-2023-42905
CVE-2023-42906
CVE-2023-42907
CVE-2023-42908
CVE-2023-42909
CVE-2023-42910
CVE-2023-42911
CVE-2023-42912
CVE-2023-42926
CVE-2023-42924
CVE-2023-42882
CVE-2023-42881
CVE-2023-42900
CVE-2023-42886
CVE-2023-42891
CVE-2023-42932
CVE-2023-5344
Disclaimer
The information provided herein is on "as is" basis, without warranty of any kind.
Contact Information
Email: info@cert-in.org.in Phone: +91-11-24368572
Postal address
Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology Government of India Electronics Niketan 6, CGO Complex, Lodhi Road, New Delhi - 110 003 India
|