PT-2023-4267 · Apple · Apple Macos

Gergely Kalman

+1

·

Published

2023-07-24

·

Updated

2024-11-07

·

CVE-2023-32364

CVSS v3.1

8.6

High

VectorAV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions macOS versions prior to 13.5
Description A logic issue was addressed with improved restrictions, allowing a sandboxed process to potentially circumvent sandbox restrictions. This issue is related to errors in security settings of the AppSandbox component in macOS, which may enable an attacker to bypass the protective mechanism of the isolated program environment.
Recommendations For versions prior to 13.5, update to macOS Ventura 13.5 to resolve the issue. As a temporary workaround, consider restricting access to sandboxed processes until the update is applied.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2023-04584
CVE-2023-32364

Affected Products

Apple Macos