cbcvebase.
CVE-2024-23245
published 2024-03-08

CVE-2024-23245: This issue was addressed by adding an additional prompt for user consent. This issue is fixed in macOS Monterey 12.7.4, macOS Sonoma 14.4, macOS Ventura…

PriorityP410low3.3CVSS 3.1
AVLACLPRNUIRSUCNILAN
EPSS
0.43%
35.6th percentile
This issue was addressed by adding an additional prompt for user consent. This issue is fixed in macOS Monterey 12.7.4, macOS Sonoma 14.4, macOS Ventura 13.6.5. Third-party shortcuts may use a legacy action from Automator to send events to apps without user consent.

Affected

9 ranges
VendorProductVersion rangeFixed in
applemacos< 12.7.412.7.4
applemacos< 13.6.513.6.5
applemacos< 14.414.4
applemacos>= 12.0 < 12.7.412.7.4
applemacos>= 13.0 < 13.6.513.6.5
applemacos>= 14.0 < 14.414.4
applemacos_monterey
applemacos_sonoma
applemacos_ventura
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.