CVE-2024-23242

Severity
3.3LOW
EPSS
0.0%
top 91.22%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 8

Description

A privacy issue was addressed by not logging contents of text fields. This issue is fixed in iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4. An app may be able to view Mail data.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:NExploitability: 1.8 | Impact: 1.4

Affected Packages5 packages

CVEListV5apple/macos< 14.4
NVDapple/macos14.014.4
NVDapple/ipad_os< 17.4
CVEListV5apple/ios_and_ipados< 17.4
NVDapple/iphone_os< 17.4

🔴Vulnerability Details

2
CVEList
CVE-2024-23242: A privacy issue was addressed by not logging contents of text fields2024-03-08
GHSA
GHSA-v2jv-c66v-hqhv: A privacy issue was addressed by not logging contents of text fields2024-03-08

📋Vendor Advisories

2
Apple
CVE-2024-23242: macOS Sonoma 14.42024-03-07
Apple
CVE-2024-23242: iOS 17.4 and iPadOS 17.42024-03-05