CVE-2024-44136
published 2025-01-15CVE-2024-44136: This issue was addressed through improved state management. This issue is fixed in iOS 17.5 and iPadOS 17.5. An attacker with physical access to a device may…
PriorityP416medium4.6CVSS 3.1
AVPACLPRNUINSUCNIHAN
EPSS
0.43%
35.3th percentile
This issue was addressed through improved state management. This issue is fixed in iOS 17.5 and iPadOS 17.5. An attacker with physical access to a device may be able to disable Stolen Device Protection.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | ios_17.5_and_ipados | — | — |
| apple | ios_and_ipados | < 17.5 | 17.5 |
| apple | ipados | < 17.5 | 17.5 |
| apple | iphone_os | < 17.5 | 17.5 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Apple
CVE-2024-44136: iOS 17.5 and iPadOS 17.5
vendor_apple·2024-05-13·CVSS 4.6
CVE-2024-44136 [MEDIUM] CVE-2024-44136: iOS 17.5 and iPadOS 17.5
Apple Security Update: About the security content of iOS 17.5 and iPadOS 17.5
Product: iOS 17.5 and iPadOS
Version: 17.5
CVE: CVE-2024-44136
Component: Face ID
Impact: An attacker with physical access to a device may be able to disable Stolen Device Protection
Description: This issue was addressed through improved state management.
GHSA
GHSA-f69c-c87p-g4rh: This issue was addressed through improved state management
ghsa_unreviewed·2025-01-15
CVE-2024-44136 [CRITICAL] CWE-863 GHSA-f69c-c87p-g4rh: This issue was addressed through improved state management
This issue was addressed through improved state management. This issue is fixed in iOS 17.5 and iPadOS 17.5. An attacker with physical access to a device may be able to disable Stolen Device Protection.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2025-01-15
Published