CVE-2023-23523
Description
Photos in the Hidden Photos Album could be viewed without authentication via Visual Lookup on macOS Ventura 13.3, iOS 16.4, and iPadOS 16.4.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Photos in the Hidden Photos Album could be viewed without authentication via Visual Lookup on macOS Ventura 13.3, iOS 16.4, and iPadOS 16.4.
Vulnerability
A logic issue in the Visual Lookup feature allowed photos in the Hidden Photos Album to be viewed without authentication. This affects macOS Ventura versions before 13.3, iOS before 16.4, and iPadOS before 16.4 [1][2]. The bug arises from insufficient restrictions when Visual Lookup processes hidden album content.
Exploitation
An attacker with physical access to the device or the ability to trigger Visual Lookup (e.g., by interacting with a photo) could bypass the hidden album's authentication. No special privileges or user interaction beyond normal usage is required; the vulnerability is triggered when Visual Lookup is invoked on a photo that belongs to the Hidden Photos Album.
Impact
Successful exploitation allows unauthorized viewing of photos from the Hidden Photos Album, bypassing the authentication protection intended to keep them private. This constitutes a privacy breach and unauthorized information disclosure.
Mitigation
The issue is fixed in macOS Ventura 13.3, iOS 16.4, and iPadOS 16.4, released on March 27, 2023 [1][2]. No workarounds have been published, and the vulnerability is not listed in CISA's Known Exploited Vulnerabilities catalog. Users should update their devices to the latest available versions.
AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
5<13.3+ 1 more
- (no CPE)range: <13.3
- (no CPE)range: unspecified
- Range: <16.4
- Range: <16.4
- Range: unspecified
Patches
0No patches discovered yet.
Vulnerability mechanics
No source-code context for this CVE — mechanics is only generated when we can read the actual fix diff. Without that, the four sections (root cause, attack vector, affected code, fix) would be speculation rather than analysis.
References
2News mentions
0No linked articles in our index yet.