CVE-2024-23289Apple IOS AND Ipados vulnerability

7 documents4 sources
Severity
3.3LOWNVD
EPSS
0.0%
top 85.84%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 8

Description

A lock screen issue was addressed with improved state management. This issue is fixed in iOS 16.7.6 and iPadOS 16.7.6, iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4, watchOS 10.4. A person with physical access to a device may be able to use Siri to access private calendar information.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:NExploitability: 1.8 | Impact: 1.4

Affected Packages7 packages

NVDapple/ipados17.017.4+1
CVEListV5apple/ios_and_ipados< 16.7.6+1
CVEListV5apple/macos< 14.4
NVDapple/macos14.014.4
CVEListV5apple/watchos< 10.4

🔴Vulnerability Details

2
GHSA
GHSA-fvm2-fqg3-334j: A lock screen issue was addressed with improved state management2024-03-08
CVEList
CVE-2024-23289: A lock screen issue was addressed with improved state management2024-03-08

📋Vendor Advisories

4
Apple
CVE-2024-23289: macOS Sonoma 14.42024-03-07
Apple
CVE-2024-23289: watchOS 10.42024-03-07
Apple
CVE-2024-23289: iOS 16.7.6 and iPadOS 16.7.62024-03-05
Apple
CVE-2024-23289: iOS 17.4 and iPadOS 17.42024-03-05
CVE-2024-23289 — Apple IOS AND Ipados vulnerability | cvebase