This issue was addressed by enabling hardened runtime. This issue is fixed in iOS 16.2 and iPadOS 16.2, macOS Ventura 13.1, tvOS 16.2, watchOS 9.2. An app may be able to bypass Privacy preferences.
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
Link | Tags |
---|---|
https://support.apple.com/en-us/HT213535 | release notes vendor advisory |
https://support.apple.com/en-us/HT213532 | release notes vendor advisory |
https://support.apple.com/en-us/HT213530 | release notes vendor advisory |
https://support.apple.com/en-us/HT213536 | release notes vendor advisory |
http://seclists.org/fulldisclosure/2022/Dec/20 | third party advisory mailing list |
http://seclists.org/fulldisclosure/2022/Dec/23 | third party advisory mailing list |
http://seclists.org/fulldisclosure/2022/Dec/26 | third party advisory mailing list |
http://seclists.org/fulldisclosure/2022/Dec/27 | mailing list |
https://support.apple.com/kb/HT213534 |