CVE-2024-27814Sensitive Information Exposure in Apple Watchos

Severity
2.4LOWNVD
EPSS
0.1%
top 68.98%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJun 10

Description

This issue was addressed through improved state management. This issue is fixed in watchOS 10.5. A person with physical access to a device may be able to view contact information from the lock screen.

CVSS vector

CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:NExploitability: 0.9 | Impact: 1.4

Affected Packages2 packages

CVEListV5apple/watchos< 10.5
NVDapple/watchos< 10.5

🔴Vulnerability Details

2
CVEList
CVE-2024-27814: This issue was addressed through improved state management2024-06-10
GHSA
GHSA-mv5f-f7c2-2pg5: This issue was addressed through improved state management2024-06-10

📋Vendor Advisories

1
Apple
CVE-2024-27814: watchOS 10.52024-05-13
CVE-2024-27814 — Sensitive Information Exposure | cvebase