7.5 CVE-2024-23204
The issue was addressed with additional permissions checks. This issue is fixed in macOS Sonoma 14.3, watchOS 10.3, iOS 17.3 and iPadOS 17.3. A shortcut may be able to use sensitive data with certain actions without prompting the user.
https://nvd.nist.gov/vuln/detail/CVE-2024-23204
Categories
CWE-NVD-noinfo
References
af854a3a-2127-422b-91ae-364da2661108
http://seclists.org/fulldisclosure/2024/Jan/33 Third Party Advisory |
http://seclists.org/fulldisclosure/2024/Jan/36 Third Party Advisory |
http://seclists.org/fulldisclosure/2024/Jan/39 Third Party Advisory |
http://seclists.org/fulldisclosure/2024/Mar/22 |
http://seclists.org/fulldisclosure/2024/Mar/23 |
https://support.apple.com/en-us/HT214059 Release Notes Vendor Advisory |
https://support.apple.com/en-us/HT214060 Release Notes Vendor Advisory |
https://support.apple.com/en-us/HT214061 Release Notes Vendor Advisory |
https://support.apple.com/kb/HT214082 |
https://support.apple.com/kb/HT214083 |
https://support.apple.com/kb/HT214085 |
product-security@apple.com
http://seclists.org/fulldisclosure/2024/Jan/33 Third Party Advisory |
http://seclists.org/fulldisclosure/2024/Jan/36 Third Party Advisory |
http://seclists.org/fulldisclosure/2024/Jan/39 Third Party Advisory |
http://seclists.org/fulldisclosure/2024/Mar/22 |
http://seclists.org/fulldisclosure/2024/Mar/23 |
https://support.apple.com/en-us/HT214059 Release Notes Vendor Advisory |
https://support.apple.com/en-us/HT214060 Release Notes Vendor Advisory |
https://support.apple.com/en-us/HT214061 Release Notes Vendor Advisory |
https://support.apple.com/kb/HT214082 |
https://support.apple.com/kb/HT214083 |
https://support.apple.com/kb/HT214085 |
CPE
cpe | start | end |
---|---|---|
Configuration 1 | ||
cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:* | > 17.0 | < 17.3 |
cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:* | > 17.0 | < 17.3 |
cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:* | < 14.3 | |
cpe:2.3:o:apple:watchos:*:*:*:*:*:*:*:* | < 10.3 |
REMEDIATION
EXPLOITS
Exploit-db.com
id | description | date | |
---|---|---|---|
No known exploits |
POC Github
Url |
---|
No known exploits |
Other Nist (github, ...)
Url |
---|
No known exploits |
CAPEC
Common Attack Pattern Enumerations and Classifications
id | description | severity |
---|---|---|
No entry |
Cybersecurity needs ?
Strengthen software security from the outset with our DevSecOps expertise
Integrate security right from the start of the software development cycle for more robust applications and greater customer confidence.
Our team of DevSecOps experts can help you secure your APIs, data pipelines, CI/CD chains, Docker containers and Kubernetes deployments.