Skip to content

Threat Research Knowledge Base

CVE-2023-40424

Description

CVE-2023-40424 is a security vulnerability in Apple's operating systems that could allow an application to access user-sensitive data. The issue was addressed by Apple through improved checks in macOS Sonoma 14.0, iOS 17, iPadOS 17, and watchOS 10. According to Kandji's analysis, this vulnerability involves the ability of a root-level user to create a new user with a custom Transparency, Consent, and Control (TCC) database in macOS. This custom TCC database can then be used to access other user's private data, effectively bypassing the intended privacy protections.

Get a Free Trial

Impact

Exploitation of this vulnerability could lead to unauthorized access to sensitive user data by an application. The severity of this issue has been assessed as follows:

NIST assessment

CVSS v3.1 Base Score: 5.5 (Medium)

AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

Has been exploited in the wild

No

Operating systems impacted

  • macOS Sonoma (prior to 14.0)
  • iOS (prior to 17)
  • iPadOS (prior to 17)
  • watchOS (prior to 10)

Apps impacted

No apps impacted

Learn more about it

Kandji Blog: How Malware Can Bypass Transparency Consent and Control

Kandji Blog: How Malware Can Bypass Transparency Consent and Control

CVE-2023-40424 allows a root-level user to bypass macOS TCC protections by creating a new user with a custom TCC database to access other users’ data, and Apple fixed it in the initial Sonoma release.

Read more

Related

Exploitation of this vulnerability could lead to unauthorized modification of protected file system areas by an application. The severity of this issue has been assessed as follows:

Exploitation of this vulnerability could lead to unauthorized access to sensitive user data by an application. The severity of this issue has been assessed as follows:

Manage and secure your Apple devices at scale.

Laptop and 2 popup windows