CVE-2023-32371 is a sandbox escape vulnerability affecting Apple iOS, iPadOS, and macOS, allowing an application to potentially bypass security restrictions. With a CVSS score of 6.3 (Medium), it requires user interaction (UI:R) and local access (AV:L) to achieve high integrity impact (I:H), though confidentiality and availability are not affected. Apple has addressed this issue with improved checks in iOS 16.5, iPadOS 16.5, and macOS Ventura 13.4. There is currently no evidence of active exploitation, public exploit code, or significant community discussion surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 16.5CPE matchmatch criteria | cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:* | ||
< 16.5CPE matchmatch criteria | cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:* | ||
>= 13.0, < 13.4CPE matchmatch criteria | cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:N/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.