Vulnerability Description
This issue was addressed by enabling hardened runtime. This issue is fixed in Xcode 15. An app may be able to access App Store credentials.
CVSS Score
5.5
MEDIUM
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Apple | Xcode | < 15.0 |
References
- http://seclists.org/fulldisclosure/2023/Oct/7Mailing ListThird Party Advisory
- https://support.apple.com/en-us/HT213939Release NotesVendor Advisory
- http://seclists.org/fulldisclosure/2023/Oct/7Mailing ListThird Party Advisory
- https://support.apple.com/en-us/HT213939Release NotesVendor Advisory
- https://support.apple.com/kb/HT213939
FAQ
What is CVE-2023-40435?
CVE-2023-40435 is a vulnerability with a CVSS score of 5.5 (MEDIUM). This issue was addressed by enabling hardened runtime. This issue is fixed in Xcode 15. An app may be able to access App Store credentials.
How severe is CVE-2023-40435?
CVE-2023-40435 has been rated MEDIUM with a CVSS base score of 5.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-40435?
Check the references section above for vendor advisories and patch information. Affected products include: Apple Xcode.