CVE-2023-42961

medium

Description

A path handling issue was addressed with improved validation. This issue is fixed in iOS 17 and iPadOS 17, iOS 16.7 and iPadOS 16.7, macOS Sonoma 14, macOS Ventura 13.6, macOS Monterey 12.7. A sandboxed process may be able to circumvent sandbox restrictions.

References

https://support.apple.com/en-us/120950

https://support.apple.com/en-us/120949

https://support.apple.com/en-us/120337

https://support.apple.com/en-us/120329

https://support.apple.com/en-us/120328

Details

Source: Mitre, NVD

Published: 2025-04-11

Updated: 2025-04-21

Risk Information

CVSS v2

Base Score: 6.5

Vector: CVSS2#AV:N/AC:L/Au:S/C:P/I:P/A:P

Severity: Medium

CVSS v3

Base Score: 6.3

Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L

Severity: Medium

EPSS

EPSS: 0.00018