CVE-2023-41982 is a vulnerability affecting Apple's macOS, watchOS, iOS, and iPadOS that allows an attacker with physical access to a locked device to potentially access sensitive user data via Siri. The CVSS score of 4.6 (Medium) indicates a low attack complexity with high confidentiality impact, requiring physical access to the device. While no public exploit code or active exploitation has been observed, Apple has released patches in macOS Sonoma 14.1, watchOS 10.1, iOS 16.7.2/17.1, and iPadOS 16.7.2/17.1 to address this issue by restricting Siri options on locked devices.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 16.7.2CPE matchmatch criteria | cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:* | ||
>= 17.0, < 17.1CPE matchmatch criteria | cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:* | ||
< 16.7.2CPE matchmatch criteria | cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:* | ||
>= 17.0, < 17.1CPE matchmatch criteria | cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:* | ||
>= 14.0, < 14.1CPE matchmatch criteria | cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.2 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.