CVE-2024-23291Apple IOS AND Ipados vulnerability

7 documents4 sources
Severity
3.3LOWNVD
EPSS
0.3%
top 49.36%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 8

Description

A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4, tvOS 17.4, watchOS 10.4. A malicious app may be able to observe user data in log entries related to accessibility notifications.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:NExploitability: 1.8 | Impact: 1.4

Affected Packages9 packages

CVEListV5apple/tvos< 17.4
NVDapple/tvos< 17.4
CVEListV5apple/macos< 14.4
NVDapple/macos14.014.4
NVDapple/ipados< 17.4

🔴Vulnerability Details

2
CVEList
CVE-2024-23291: A privacy issue was addressed with improved private data redaction for log entries2024-03-08
GHSA
GHSA-c534-6v46-r777: A privacy issue was addressed with improved private data redaction for log entries2024-03-08

📋Vendor Advisories

4
Apple
CVE-2024-23291: macOS Sonoma 14.42024-03-07
Apple
CVE-2024-23291: tvOS 17.42024-03-07
Apple
CVE-2024-23291: watchOS 10.42024-03-07
Apple
CVE-2024-23291: iOS 17.4 and iPadOS 17.42024-03-05
CVE-2024-23291 — Apple IOS AND Ipados vulnerability | cvebase