Threat Research Knowledge Base Vulnerabilities CVE-2023-40424
CVE-2023-40424
Description
CVE-2023-40424 is a security vulnerability in Apple's operating systems that could allow an application to access user-sensitive data. The issue was addressed by Apple through improved checks in macOS Sonoma 14.0, iOS 17, iPadOS 17, and watchOS 10. According to Kandji's analysis, this vulnerability involves the ability of a root-level user to create a new user with a custom Transparency, Consent, and Control (TCC) database in macOS. This custom TCC database can then be used to access other user's private data, effectively bypassing the intended privacy protections.
Impact
Exploitation of this vulnerability could lead to unauthorized access to sensitive user data by an application. The severity of this issue has been assessed as follows:
NIST assessment
CVSS v3.1 Base Score: 5.5 (Medium)
AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
Has been exploited in the wild
No
Operating systems impacted
- macOS Sonoma (prior to 14.0)
- iOS (prior to 17)
- iPadOS (prior to 17)
- watchOS (prior to 10)
Additional resources
Apps impacted
No apps impacted
Learn more about it

Kandji Blog: How Malware Can Bypass Transparency Consent and Control
CVE-2023-40424 allows a root-level user to bypass macOS TCC protections by creating a new user with a custom TCC database to access other users’ data, and Apple fixed it in the initial Sonoma release.
Read moreRelated
Exploitation of this vulnerability could lead to unauthorized modification of protected file system areas by an application. The severity of this issue has been assessed as follows:
Exploitation of this vulnerability could lead to unauthorized access to sensitive user data by an application. The severity of this issue has been assessed as follows:
Manage and secure your Apple devices at scale.
