PT-2024-30973 · Apple · Ipados+3

Denis Tokarev

+1

·

Published

2024-09-16

·

Updated

2025-05-14

·

CVE-2024-44131

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions iOS versions prior to 18 iPadOS versions prior to 18 macOS Sequoia versions prior to 15
Description This issue was addressed with improved validation of symlinks, allowing unauthorized apps to access sensitive user data, including Health information, microphone, and iCloud backups, without user consent or knowledge. The vulnerability affects the Transparency, Consent, and Control (TCC) subsystem, which is designed to protect sensitive data.
Recommendations Update to iOS 18 to fix the issue. Update to iPadOS 18 to fix the issue. Update to macOS Sequoia 15 to fix the issue.

Fix

Link Following

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-44131

Affected Products

Apple Macos
Ios
Ipados
Macos Sequoia