PT-2024-1415 · Apple · Magic Keyboard
Marc Newlin
·
Published
2024-01-11
·
Updated
2026-03-13
·
CVE-2024-0230
CVSS v3.1
2.4
Low
| Vector | AV:P/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Magic Keyboard versions prior to 2.0.6
Description
A session management issue was addressed with improved checks. An attacker with physical access to the accessory may be able to extract its Bluetooth pairing key and monitor Bluetooth traffic. The issue is related to the management of user sessions and can be exploited to gain unauthorized access to Bluetooth traffic.
Recommendations
For Magic Keyboard versions prior to 2.0.6, update to Magic Keyboard Firmware Update 2.0.6 to fix the issue. As a temporary workaround, consider restricting physical access to the accessory to minimize the risk of exploitation.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Magic Keyboard