CVE-2023-32428

Published Sep 6, 2023

Last updated 4 months ago

Overview

Description
This issue was addressed with improved file handling. This issue is fixed in macOS Ventura 13.4, tvOS 16.5, iOS 16.5 and iPadOS 16.5, watchOS 9.5. An app may be able to gain root privileges.
Source
product-security@apple.com
NVD status
Modified

Risk scores

CVSS 3.1

Type
Primary
Base score
7.8
Impact score
5.9
Exploitability score
1.8
Vector string
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Severity
HIGH

Weaknesses

nvd@nist.gov
NVD-CWE-noinfo

Social media

Hype score
Not currently trending
  1. CVE-2023-32428 macOS Ventura 13.4, tvOS 16.5, iOS 16.5 and iPadOS 16.5, watchOS 9.5 The issue with macOS is an LPE via Malloc Stack Logging, which is addressed with improved file handling. The attacker may be able to gain root privileges as a result. This vulnerability exists in

    @PPHM_HackerNews

    15 Mar 2025

    101 Impressions

    0 Retweets

    2 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  2. Threat Alert: macOS Vulnerability (CVE-2023-32428) Grants Root Access, PoC Published CVE-2023-32428 Severity: 🔴 High Maturity: 💢 Emerging Learn more: https://t.co/S0I2E1ecCu #CyberSecurity #ThreatIntel #InfoSec

    @fletch_ai

    3 Dec 2024

    18 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  3. #exploit 1. CVE-2023-5717: Linux Kernel Perf OOB write https://t.co/OrswxjrtZb 2. CVE-2023-32428: macOS LPE via Malloc Stack Logging https://t.co/rvTmmxSNLh ]-> PoC 3. CVE-2024-44175: macOS diskarbitrationd Symlink Validation (TOCTOU LPE) https://t.co/sK8bF6BUIH

    @ksg93rd

    30 Nov 2024

    255 Impressions

    5 Retweets

    8 Likes

    1 Bookmark

    0 Replies

    0 Quotes

  4. badmalloc (CVE-2023-32428) - a macOS LPE https://t.co/bWjyDue5QY #Pentesting #CyberSecurity #Infosec https://t.co/YBlj3m4zAc

    @ptracesecurity

    28 Nov 2024

    1641 Impressions

    5 Retweets

    29 Likes

    8 Bookmarks

    0 Replies

    0 Quotes

  5. macOSでroot権限を取得可能なローカル権限昇格脆弱性CVE-2023-32428について、Poc(攻撃の概念実証コード)が公開された。MallocStackLoggingフレームワークにおける脆弱性で、このフレームワークは特別な権限無しに任意のプロセスにロードされることが可能な点を悪用。 https://t.co/mv2RwX3B2m

    @__kokumoto

    27 Nov 2024

    2148 Impressions

    14 Retweets

    37 Likes

    5 Bookmarks

    0 Replies

    0 Quotes

  6. macOS Vulnerability (CVE-2023-32428) Grants Root Access, PoC Published https://t.co/REwku94M7o

    @Dinosn

    27 Nov 2024

    19397 Impressions

    110 Retweets

    314 Likes

    98 Bookmarks

    3 Replies

    1 Quote

Configurations