Threat Research Knowledge Base Vulnerabilities CVE-2023-42860
CVE-2023-42860
Description
CVE-2023-42860 is a permissions issue within Apple's PackageKit framework that could allow an application to modify protected parts of the file system. The vulnerability was addressed by Apple through additional restrictions in macOS Monterey 12.7.1, macOS Ventura 13.6.1, and macOS Sonoma 14.1. According to Kandji's analysis, this vulnerability allowed an attacker to swap the installer package after the system verified its code signature. The system would then install the supplied package instead of the original, enabling the attacker to bypass System Integrity Protection (SIP).
Impact
Exploitation of this vulnerability could lead to unauthorized modification of protected file system areas by an application. The severity of this issue has been assessed as follows:
NIST assessment
CVSS v3.1 Base Score: 5.5 (Medium)
AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
CISA-ADP assessment
CVSS v3.1 Base Score: 7.7 (High)
AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Has been exploited in the wild
No
Operating systems impacted
- macOS Monterey (prior to 12.7.1)
- macOS Ventura (prior to 13.6.1)
- macOS Sonoma (prior to 14.1)
Additional resources
Apps impacted
No apps impacted
Learn more about it

Kandji Blog: Apple Mitigates Vulnerabilities in Installer Scripts
Examines Apple’s steps to mitigate installer-script vulnerabilities by redesigning the PackageKit private framework after reviewing past exploit methods.
Read moreRelated
Exploitation of this vulnerability could lead to unauthorized modification of protected file system areas by an application. The severity of this issue has been assessed as follows:
Exploitation of this vulnerability could lead to unauthorized modification of protected file system areas by an application. The severity of this issue has been assessed as follows:
Exploitation of this vulnerability could lead to unauthorized access to sensitive user data by an application. The severity of this issue has been assessed as follows:
Manage and secure your Apple devices at scale.
