CVE-2023-42907: Apple macOS

High severity, CVSS 7.8. EPSS: 0.3% chance of exploitation in the next 30 days.

Multiple memory corruption issues were addressed with improved input validation. This issue is fixed in macOS Sonoma 14.2. Processing a maliciously crafted file may lead to unexpected app termination or arbitrary code execution.

Affected products

  • Apple macOS: from 14.0, before 14.2 (fixed in 14.2)

Published 2023-12-12. Last modified 2026-06-17.