This issue was addressed by forcing hardened runtime on the affected binaries at the system level. This issue is fixed in macOS Monterey 12.6.6, macOS Big Sur 11.7.7, macOS Ventura 13.4. An app may be able to inject code into sensitive binaries bundled with Xcode.
CVSS Details
- CVSS 3.1 Base Score: 7.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Apple Osx Accessibility | — | — | Oct 14, 2024 | Jan 10, 2024 |
| Apple Osx Accounts | — | — | Oct 14, 2024 | Jan 10, 2024 |
| Apple Osx Amd | — | — | Oct 14, 2024 | Jan 10, 2024 |
| Apple Osx Applemobilefileintegrity | — | Upgrade macOS to the latest version | Dec 22, 2023 | May 18, 2023 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub