Apple Security Updates – 12 December 2023

Apple has released security updates to address multiple vulnerabilities across macOS Monterey, Ventura, Sonoma and Safari.

The addressed vulnerabilities could allow the attacker to bypass security restrictions, gain elevated privileges, obtain sensitive information, execute arbitrary code, and gain access to the affected systems by persuading the victim to visit a specially crafted website.

Sample of the addressed vulnerabilities:

1. Bluetooth Privilege Escalation Flaw in macOS Sonoma (CVE-2023-45866):

  • CVSS: 9.8
  • Attack Vector: Network
  • Attack Complexity: Low
  • Privileges Required: None
  • User Interaction: None
  • Consequences: Gain Privileges

2. Apple Safari Code Execution Vulnerability (CVE-2023-42890):

  • CVSS: 8.8
  • Attack Vector: Network
  • Attack Complexity: Low
  • Privileges Required: None
  • User Interaction: Required
  • Consequences: Gain Access
Vulnerabilities
Mitigations

The enterprise should deploy this patch as soon as the testing phase is completed.

Apple Security Advisory

References