PT-2023-8484 · Apple · Apple Macos

Berke Kırbaş

+1

·

Published

2023-09-26

·

Updated

2024-01-17

·

CVE-2023-40393

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions macOS versions prior to 14
Description An authentication issue was addressed with improved state management, allowing photos in the Hidden Photos Album to be viewed without authentication. The issue is related to a lack of authentication for a critical function, which could be exploited by a remote attacker to view the "Hidden Photos Album" without authentication.
Recommendations For versions prior to macOS 14, update to macOS Sonoma 14 to resolve the issue. As a temporary workaround, consider restricting access to the Hidden Photos Album until the update is applied.

Fix

Missing Authentication

Weakness Enumeration

Related Identifiers

BDU:2024-00963
CVE-2023-40393

Affected Products

Apple Macos