---
cve: "CVE-2023-42872"
severity: "MEDIUM"
cvss: 5.5
epss: "20%"
vendor: "Apple"
kev: false
exploited: false
published: "2024-01-10 22:15:50"
tags: [cve, security, medium]
source: tsecurity.de CVE-Dossier
exported: "2026-09-15T12:39:25+02:00"
---

# CVE-2023-42872

> 5.5 MEDIUM

## Beschreibung

The issue was addressed with additional permissions checks. This issue is fixed in macOS Sonoma 14, iOS 17 and iPadOS 17. An app may be able to access sensitive user data.

## CVSS-Vektor

```
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
```

| Metrik | Wert | Bewertung |
|---|---|---|
| AV Angriffsvektor | Lokal | good |
| AC Komplexität | Gering | bad |
| PR Privilegien | Keine | bad |
| UI Interaktion | Erforderlich | good |
| S Scope | Unverändert | good |
| C Vertraulichkeit | Hoch | bad |
| I Integrität | Keine | good |
| A Verfügbarkeit | Keine | good |

## Referenzen

- <https://support.apple.com/en-us/HT213938>
- <https://support.apple.com/en-us/HT213940>
- <https://support.apple.com/kb/HT213938>
- <https://support.apple.com/kb/HT213940>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2023-42872) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI BITS_
