CVE-2023-40541: Apple macOS

Medium severity, CVSS 5.5. EPSS: 0.3% chance of exploitation in the next 30 days.

This issue was addressed by adding an additional prompt for user consent. This issue is fixed in macOS Sonoma 14. A shortcut may output sensitive user data without consent.

Affected products

  • Apple macOS: before 14.0 (fixed in 14.0)

Published 2023-09-27. Last modified 2026-06-17.