CVE-2023-42873 is a kernel vulnerability affecting Apple's macOS, iOS, iPadOS, and tvOS that could allow an application to execute arbitrary code with kernel privileges due to insufficient bounds checks. This high-severity vulnerability (CVSS 7.8) requires local access and user interaction, potentially leading to full compromise of confidentiality, integrity, and availability. While no active exploitation, public exploit code, or significant community discussion has been observed, users are strongly advised to apply the available patches in macOS Sonoma 14.1, tvOS 17.1, macOS Monterey 12.7.1, iOS 16.7.2/17.1, iPadOS 16.7.2/17.1, and macOS Ventura 13.6.1.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 17.1CPE matchmatch criteria | cpe:2.3:o:apple:ipad_os:*:*:*:*:*:*:*:* | ||
>= 16.0, < 16.7.2CPE matchmatch criteria | cpe:2.3:o:apple:ipad_os:*:*:*:*:*:*:*:* | ||
< 17.1CPE matchmatch criteria | cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:* | ||
>= 16.0, < 16.7.2CPE matchmatch criteria | cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:* | ||
>= 12.0, < 12.7.1CPE matchmatch criteria | cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.