CVE-2023-40438

An issue was addressed with improved handling of temporary files. This issue is fixed in macOS Sonoma 14, iOS 16.7 and iPadOS 16.7. An app may be able to access edited photos saved to a temporary directory.
References
Link Resource
https://support.apple.com/en-us/HT213927 Release Notes Vendor Advisory
https://support.apple.com/en-us/HT213940 Release Notes Vendor Advisory
https://support.apple.com/en-us/HT213927 Release Notes Vendor Advisory
https://support.apple.com/en-us/HT213940 Release Notes Vendor Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*

History

20 Jun 2025, 16:15

Type Values Removed Values Added
CWE CWE-379

21 Nov 2024, 08:19

Type Values Removed Values Added
References () https://support.apple.com/en-us/HT213927 - Release Notes, Vendor Advisory () https://support.apple.com/en-us/HT213927 - Release Notes, Vendor Advisory
References () https://support.apple.com/en-us/HT213940 - Release Notes, Vendor Advisory () https://support.apple.com/en-us/HT213940 - Release Notes, Vendor Advisory

16 Jan 2024, 23:51

Type Values Removed Values Added
CWE NVD-CWE-noinfo
References () https://support.apple.com/en-us/HT213927 - () https://support.apple.com/en-us/HT213927 - Release Notes, Vendor Advisory
References () https://support.apple.com/en-us/HT213940 - () https://support.apple.com/en-us/HT213940 - Release Notes, Vendor Advisory
First Time Apple iphone Os
Apple macos
Apple ipados
Apple
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.5
CPE cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*

11 Jan 2024, 13:57

Type Values Removed Values Added
Summary
  • (es) Se solucionó un problema con el manejo mejorado de archivos temporales. Este problema se solucionó en macOS Sonoma 14, iOS 16.7 y iPadOS 16.7. Es posible que una aplicación pueda acceder a fotos editadas guardadas en un directorio temporal.

10 Jan 2024, 22:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-01-10 22:15

Updated : 2025-06-20 16:15


NVD link : CVE-2023-40438

Mitre link : CVE-2023-40438

CVE.ORG link : CVE-2023-40438


JSON object : View

Products Affected

apple

  • iphone_os
  • ipados
  • macos
CWE
NVD-CWE-noinfo CWE-379

Creation of Temporary File in Directory with Insecure Permissions