Apple Security Updates – 21 May 2023

Apple has released security updates to address multiple vulnerabilities across macOS Ventura, macOS Monterey, macOS Big Sur, and Safari. The mentioned updates contain fixes for three zero-day vulnerabilities.

The addressed vulnerabilities could allow the attacker to gain access, escalate privileges, bypass security restrictions, obtain information, or execute arbitrary code on the affected systems.

Sample of the addressed vulnerabilities:

1. Apple macOS Ventura, and Safari Code Execution Vulnerability (CVE-2023-32373):

  • CVSS: 8.8
  • Attack Vector: Network
  • Attack Complexity: Low
  • Privileges Required: None
  • User Interaction: Required
  • Consequences: Gain Access

2. Apple macOS Big Sur Privilege Escalation (CVE-2023-32405):

  • CVSS: 8.4
  • Attack Vector: Local
  • Attack Complexity: Low
  • Privileges Required: None
  • User Interaction: None
  • Consequences: Gain Privileges

It should be highlighted that Apple is aware of three zero-day vulnerabilities tracked as CVE-2023-32409, CVE-2023-28204, and CVE-2023-32373 that have been actively exploited in the wild.

Vulnerabilities
Mitigations

The enterprise should deploy this patch as soon as the testing phase is completed.

Apple Security Advisory

References