CVE-2023-41968 is a local vulnerability affecting Apple's iOS, iPadOS, macOS, tvOS, and watchOS that could allow an application to read arbitrary files due to insufficient symlink validation. With a CVSS score of 5.5 (Medium), it requires user interaction and local access for exploitation, potentially leading to high confidentiality impact. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion, indicating low current threat activity. Apple has addressed this issue in macOS Ventura 13.6, tvOS 17, macOS Monterey 12.7, watchOS 10, iOS 17, iPadOS 17, and macOS Sonoma 14.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 17.0CPE matchmatch criteria | cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:* | ||
< 17.0CPE matchmatch criteria | cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:* | ||
>= 12.0.0, < 12.7CPE matchmatch criteria | cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:* | ||
>= 13.0, < 13.6CPE matchmatch criteria | cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:* | ||
< 17.0CPE matchmatch criteria | cpe:2.3:o:apple:tvos:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.