Apple · Apple Macos · CVE-2023-40393
**Name of the Vulnerable Software and Affected Versions**
macOS versions prior to 14
**Description**
An authentication issue was addressed with improved state management, allowing photos in the Hidden Photos Album to be viewed without authentication. The issue is related to a lack of authentication for a critical function, which could be exploited by a remote attacker to view the "Hidden Photos Album" without authentication.
**Recommendations**
For versions prior to macOS 14, update to macOS Sonoma 14 to resolve the issue. As a temporary workaround, consider restricting access to the Hidden Photos Album until the update is applied.