CVE-2023-40401

Severity CVSS v4.0:
Pending analysis
Type:
CWE-306 Missing Authentication for Critical Function
Publication date:
25/10/2023
Last modified:
22/12/2023

Description

The issue was addressed with additional permissions checks. This issue is fixed in macOS Ventura 13.6.1. An attacker may be able to access passkeys without authentication.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:* 13.0 (including) 13.6.1 (excluding)