CVE-2023-42886: Apple macOS

High severity, CVSS 7.8. EPSS: 0.3% chance of exploitation in the next 30 days.

An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Sonoma 14.2, macOS Ventura 13.6.3, macOS Monterey 12.7.2. A user may be able to cause unexpected app termination or arbitrary code execution.

Affected products

  • Apple macOS: from 12.0.0, before 12.7.2 (fixed in 12.7.2); from 13.0, before 13.6.3 (fixed in 13.6.3); from 14.0, before 14.2 (fixed in 14.2)

Published 2023-12-12. Last modified 2026-06-17.