VYPR
Unrated severityNVD Advisory· Published Jun 23, 2023· Updated Dec 5, 2024

CVE-2023-32394

CVE-2023-32394

Description

A lock screen issue in Apple devices allowed physical access to view contact info; fixed in iOS 16.5, iPadOS 16.5, macOS Ventura 13.4, watchOS 9.5, tvOS 16.5.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

A lock screen issue in Apple devices allowed physical access to view contact info; fixed in iOS 16.5, iPadOS 16.5, macOS Ventura 13.4, watchOS 9.5, tvOS 16.5.

Vulnerability

A lock screen vulnerability in Apple operating systems allows a person with physical access to a device to view contact information without authentication. The issue affects iOS 16.5 and iPadOS 16.5, watchOS 9.5, tvOS 16.5, and macOS Ventura 13.4. The bug was addressed with improved checks [1][2][3][4].

Exploitation

An attacker needs physical access to the locked device. No authentication or special privileges are required; the attacker can simply interact with the lock screen to access contact information. The specific sequence of steps is not detailed in the available references, but the vulnerability is present on the lock screen before the device is unlocked [1][2][3][4].

Impact

A person with physical access can view contact information stored on the device, leading to a disclosure of personal data. The information accessible may include names, phone numbers, email addresses, and other contact details. No other impacts are documented in the references [1][2][3][4].

Mitigation

Apple released fixes on May 18, 2023, as part of iOS 16.5 and iPadOS 16.5, watchOS 9.5, tvOS 16.5, and macOS Ventura 13.4. Users should update their devices to the latest available versions. No workarounds are provided in the references; the only mitigation is to apply the updates [1][2][3][4].

AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

7

Patches

0

No patches discovered yet.

Vulnerability mechanics

No source-code context for this CVE — mechanics is only generated when we can read the actual fix diff. Without that, the four sections (root cause, attack vector, affected code, fix) would be speculation rather than analysis.

References

4

News mentions

0

No linked articles in our index yet.