PT-2024-19789 · Visionos · Visionos

Patrick Reardon

·

Published

2024-03-07

·

Updated

2024-12-09

·

CVE-2024-23295

CVSS v3.1

6.2

Medium

VectorAV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions visionOS versions prior to 1.1
Description A permissions issue was addressed to help ensure Personas are always protected. An unauthenticated user may be able to use an unprotected Persona.
Recommendations For versions prior to 1.1, update to visionOS 1.1 to resolve the issue. As a temporary workaround, consider restricting access to Personas to prevent unauthorized use until the update is applied.

Fix

Incorrect Default Permissions

Weakness Enumeration

Related Identifiers

CVE-2024-23295

Affected Products

Visionos