Apple Security Updates – 03 December 2023

Apple has released security updates to address multiple vulnerabilities across macOS Monterey, Ventura, Sonoma and Safari.

The addressed vulnerabilities could allow the remote attacker to obtain sensitive information, execute arbitrary code, and gain access to the affected systems by persuading the victim to visit a specially crafted website.

The addressed vulnerabilities:

1. Apple Safari, and macOS Code Execution Vulnerability (CVE-2023-42917):

  • CVSS: 8.8
  • Attack Vector: Network
  • Attack Complexity: Low
  • Privileges Required: None
  • User Interaction: Required
  • Consequences: Gain Access

2. Apple Safari, macOS Information Disclosure Vulnerability (CVE-2023-42916):

  • CVSS: 6.5
  • Attack Vector: Network
  • Attack Complexity: Low
  • Privileges Required: None
  • User Interaction: Required
  • Consequences: Obtain Information
Vulnerabilities
  • CVE-2023-42916
  • CVE-2023-42917
Mitigations

The enterprise should deploy this patch as soon as the testing phase is completed.

Apple Security Advisory

References