The issue was addressed by restricting options offered on a locked device. This issue is fixed in macOS Sonoma 14.1. An attacker may be able to execute arbitrary code as root from the Lock Screen.
CVSS Details
- CVSS 3.1 Base Score: 6.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Apple Osx Accounts | — | — | Oct 14, 2024 | Oct 25, 2023 |
| Apple Osx Appleevents | — | — | Oct 14, 2024 | Oct 25, 2023 |
| Apple Osx Archiveutility | — | — | Oct 14, 2024 | Oct 25, 2023 |
| Apple Osx Assets | — | — | Oct 14, 2024 | Oct 25, 2023 |
| Apple Osx Automation | — | — | Oct 14, 2024 | Oct 25, 2023 |
| Apple Osx Avevideoencoder | — | — | Oct 14, 2024 | Oct 25, 2023 |
| Apple Osx Coreservices | — | — | Oct 14, 2024 | Oct 25, 2023 |
| Apple Osx Diskarbitration | — | — | Oct 14, 2024 | Oct 25, 2023 |
| Apple Osx Emoji | — | Upgrade macOS to the latest version | Oct 31, 2023 | Oct 25, 2023 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub