The issue was addressed with improved validation of environment variables. This issue is fixed in iOS 16.6 and iPadOS 16.6. An app may be able to access sensitive user data.
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://support.apple.com/en-us/HT213841 |
|
History
Fri, 20 Jun 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-20 | |
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: apple
Published: 2024-01-10T22:03:53.741Z
Updated: 2025-06-20T15:39:33.574Z
Reserved: 2023-08-14T20:26:36.253Z
Link: CVE-2023-40394
Updated: 2024-08-02T18:31:53.781Z
Status : Modified
Published: 2024-01-10T22:15:48.593
Modified: 2025-06-20T16:15:22.113
Link: CVE-2023-40394
No data.