{"dataType":"CVE_RECORD","cveMetadata":{"cveId":"CVE-2023-40389","assignerOrgId":"286789f9-fbc2-4510-9f9a-43facdede74c","state":"PUBLISHED","assignerShortName":"apple","dateReserved":"2023-08-14T20:26:36.253Z","datePublished":"2024-06-10T19:21:22.255Z","dateUpdated":"2025-11-04T18:16:40.873Z"},"containers":{"cna":{"problemTypes":[{"descriptions":[{"lang":"en","description":"An app may be able to access sensitive user data"}]}],"affected":[{"vendor":"Apple","product":"macOS","versions":[{"version":"unspecified","status":"affected","lessThan":"12.7","versionType":"custom"}]},{"vendor":"Apple","product":"macOS","versions":[{"version":"unspecified","status":"affected","lessThan":"13.6","versionType":"custom"}]}],"descriptions":[{"lang":"en","value":"The issue was addressed with improved restriction of data container access. This issue is fixed in macOS Ventura 13.6.5, macOS Monterey 12.7.4. An app may be able to access sensitive user data."}],"references":[{"url":"https://support.apple.com/en-us/HT214083"},{"url":"https://support.apple.com/en-us/HT214085"},{"url":"https://support.apple.com/kb/HT214040"},{"url":"https://support.apple.com/kb/HT214036"},{"url":"https://support.apple.com/kb/HT214035"},{"url":"https://support.apple.com/kb/HT214041"}],"providerMetadata":{"orgId":"286789f9-fbc2-4510-9f9a-43facdede74c","shortName":"apple","dateUpdated":"2024-07-17T02:05:56.295Z"}},"adp":[{"problemTypes":[{"descriptions":[{"type":"CWE","lang":"en","description":"CWE-noinfo Not enough information"}]}],"metrics":[{"cvssV3_1":{"scope":"UNCHANGED","version":"3.1","baseScore":5.5,"attackVector":"LOCAL","baseSeverity":"MEDIUM","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","integrityImpact":"NONE","userInteraction":"NONE","attackComplexity":"LOW","availabilityImpact":"NONE","privilegesRequired":"LOW","confidentialityImpact":"HIGH"}},{"other":{"type":"ssvc","content":{"timestamp":"2024-06-12T13:42:53.155176Z","id":"CVE-2023-40389","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2024-11-07T17:06:40.231Z"}},{"title":"CVE Program Container","references":[{"url":"https://support.apple.com/en-us/HT214083","tags":["x_transferred"]},{"url":"https://support.apple.com/en-us/HT214085","tags":["x_transferred"]},{"url":"https://support.apple.com/kb/HT214040","tags":["x_transferred"]},{"url":"https://support.apple.com/kb/HT214036","tags":["x_transferred"]},{"url":"https://support.apple.com/kb/HT214035","tags":["x_transferred"]},{"url":"https://support.apple.com/kb/HT214041","tags":["x_transferred"]},{"url":"https://support.apple.com/kb/HT214085"},{"url":"https://support.apple.com/kb/HT214083"}],"providerMetadata":{"orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE","dateUpdated":"2025-11-04T18:16:40.873Z"}}]},"dataVersion":"5.2"}