PT-2023-4267 · Apple · Apple Macos
Gergely Kalman
+1
·
Published
2023-07-24
·
Updated
2024-11-07
·
CVE-2023-32364
CVSS v3.1
8.6
High
| Vector | AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
macOS versions prior to 13.5
Description
A logic issue was addressed with improved restrictions, allowing a sandboxed process to potentially circumvent sandbox restrictions. This issue is related to errors in security settings of the AppSandbox component in macOS, which may enable an attacker to bypass the protective mechanism of the isolated program environment.
Recommendations
For versions prior to 13.5, update to macOS Ventura 13.5 to resolve the issue. As a temporary workaround, consider restricting access to sandboxed processes until the update is applied.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Apple Macos