CVE-2024-23297
published 2024-03-08CVE-2024-23297: The issue was addressed with improved checks. This issue is fixed in iOS 17.4 and iPadOS 17.4, tvOS 17.4, watchOS 10.4. A malicious application may be able to…
PriorityP422medium5.5CVSS 3.1
AVLACLPRNUIRSUCHINAN
EPSS
0.28%
20.5th percentile
The issue was addressed with improved checks. This issue is fixed in iOS 17.4 and iPadOS 17.4, tvOS 17.4, watchOS 10.4. A malicious application may be able to access private information.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | ios_17.4_and_ipados | — | — |
| apple | ios_and_ipados | < 17.4 | 17.4 |
| apple | ipad_os | < 17.4 | 17.4 |
| apple | iphone_os | < 17.4 | 17.4 |
| apple | tvos | < 17.4 | 17.4 |
| apple | tvos | — | — |
| apple | watchos | < 10.4 | 10.4 |
| apple | watchos | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Apple
CVE-2024-23297: tvOS 17.4
vendor_apple·2024-03-07·CVSS 5.5
CVE-2024-23297 [MEDIUM] CVE-2024-23297: tvOS 17.4
Apple Security Update: About the security content of tvOS 17.4
Product: tvOS
Version: 17.4
CVE: CVE-2024-23297
Component: MediaRemote
Impact: A malicious application may be able to access private information
Description: The issue was addressed with improved checks.
Apple
CVE-2024-23297: watchOS 10.4
vendor_apple·2024-03-07·CVSS 5.5
CVE-2024-23297 [MEDIUM] CVE-2024-23297: watchOS 10.4
Apple Security Update: About the security content of watchOS 10.4
Product: watchOS
Version: 10.4
CVE: CVE-2024-23297
Component: MediaRemote
Impact: A malicious application may be able to access private information
Description: The issue was addressed with improved checks.
Apple
CVE-2024-23297: iOS 17.4 and iPadOS 17.4
vendor_apple·2024-03-05·CVSS 5.5
CVE-2024-23297 [MEDIUM] CVE-2024-23297: iOS 17.4 and iPadOS 17.4
Apple Security Update: About the security content of iOS 17.4 and iPadOS 17.4
Product: iOS 17.4 and iPadOS
Version: 17.4
CVE: CVE-2024-23297
Component: MediaRemote
Impact: A malicious application may be able to access private information
Description: The issue was addressed with improved checks.
GHSA
GHSA-ggwq-65m4-2gf3: The issue was addressed with improved checks
ghsa_unreviewed·2024-03-08
CVE-2024-23297 [MEDIUM] GHSA-ggwq-65m4-2gf3: The issue was addressed with improved checks
The issue was addressed with improved checks. This issue is fixed in tvOS 17.4, iOS 17.4 and iPadOS 17.4, watchOS 10.4. A malicious application may be able to access private information.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://support.apple.com/en-us/120881https://support.apple.com/en-us/120882https://support.apple.com/en-us/120893http://seclists.org/fulldisclosure/2024/Mar/24http://seclists.org/fulldisclosure/2024/Mar/25https://support.apple.com/en-us/HT214081https://support.apple.com/en-us/HT214086https://support.apple.com/en-us/HT214088https://support.apple.com/kb/HT214081https://support.apple.com/kb/HT214086https://support.apple.com/kb/HT214088
2024-03-08
Published