PT-2023-8346 · Apple · Apple Macos

Mickey Jin

·

Published

2023-12-11

·

Updated

2023-12-14

·

CVE-2023-42900

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions macOS versions prior to 14.2
Description The issue is related to insufficient access control in the CoreMedia Playback component of the macOS operating system. It may allow an attacker to disclose protected information. An app may be able to access user-sensitive data. The issue was addressed with improved checks.
Recommendations For versions prior to 14.2, update to macOS Sonoma 14.2 to resolve the issue.

Fix

Improper Access Control

Weakness Enumeration

Related Identifiers

BDU:2024-00535
CVE-2023-42900

Affected Products

Apple Macos