VYPR
Unrated severityNVD Advisory· Published Jan 10, 2024· Updated Jun 16, 2025

CVE-2023-32401

CVE-2023-32401

Description

A buffer overflow was addressed with improved bounds checking. This issue is fixed in macOS Monterey 12.6.6, macOS Big Sur 11.7.7, macOS Ventura 13.4. Parsing an office document may lead to an unexpected app termination or arbitrary code execution.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

A buffer overflow in macOS office document parsing could lead to app termination or arbitrary code execution, fixed in macOS 13.4, 12.6.6, and 11.7.7.

Vulnerability

A buffer overflow vulnerability exists in the parsing of office documents across all supported macOS versions prior to macOS Ventura 13.4, macOS Monterey 12.6.6, and macOS Big Sur 11.7.7. The flaw occurs due to insufficient bounds checking when processing crafted office documents. An attacker can exploit this by providing a malicious document to a user on an affected system. [1]

Exploitation

An attacker requires the ability to deliver a specially crafted office document to the target user. The user must open the malicious document in an application that parses office file formats, such as TextEdit, Preview, or any other macOS component that handles office documents. No additional authentication or network position is required beyond the delivery of the document. [1]

Impact

Successful exploitation of this buffer overflow can lead to an unexpected app termination or arbitrary code execution. An attacker who achieves code execution could gain the privileges of the user running the vulnerable application, potentially allowing further compromise of the system. The impact is primarily on availability (app termination) and integrity/confidentiality (arbitrary code execution). [1]

Mitigation

Apple addressed this issue by improving bounds checking in the following software updates: macOS Ventura 13.4, macOS Monterey 12.6.6, and macOS Big Sur 11.7.7, all released on May 18, 2023. Users should update to the latest available version of macOS to obtain the fix. No workarounds are provided for unpatched systems. [1]

AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

4

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

3

News mentions

0

No linked articles in our index yet.