The issue was addressed with improved validation of environment variables. This issue is fixed in iOS 16.6 and iPadOS 16.6. An app may be able to access sensitive user data.
References
Link | Resource |
---|---|
https://support.apple.com/en-us/HT213841 | Release Notes Vendor Advisory |
https://support.apple.com/en-us/HT213841 | Release Notes Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
21 Nov 2024, 08:19
Type | Values Removed | Values Added |
---|---|---|
References | () https://support.apple.com/en-us/HT213841 - Release Notes, Vendor Advisory |
18 Jan 2024, 14:31
Type | Values Removed | Values Added |
---|---|---|
First Time |
Apple
Apple ipados Apple iphone Os |
|
CPE | cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:* cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:* |
|
References | () https://support.apple.com/en-us/HT213841 - Release Notes, Vendor Advisory | |
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 3.3 |
CWE | NVD-CWE-noinfo |
10 Jan 2024, 22:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-01-10 22:15
Updated : 2024-11-21 08:19
NVD link : CVE-2023-40394
Mitre link : CVE-2023-40394
CVE.ORG link : CVE-2023-40394
JSON object : View
Products Affected
apple
- ipados
- iphone_os
CWE