CVE-2023-42867: Apple Garageband

High severity, CVSS 7.8. EPSS: 0.2% chance of exploitation in the next 30 days.

This issue was addressed with improved validation of the process entitlement and Team ID. This issue is fixed in GarageBand 10.4.9. An app may be able to gain root privileges.

Affected products

  • Apple Garageband: before 10.4.9 (fixed in 10.4.9)

Published 2024-12-20. Last modified 2026-06-17.