PT-2024-3896 · Apple · Ipados+4
H33Tjubaer
+1
·
Published
2024-01-22
·
Updated
2026-03-05
·
CVE-2024-23204
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:C/I:N/A:N |
Name of the Vulnerable Software and Affected Versions:
macOS Sonoma versions prior to 14.3
watchOS versions prior to 10.3
iOS versions prior to 17.3
iPadOS versions prior to 17.3
Description:
The issue is related to the Apple Shortcuts app, where a shortcut may be able to use sensitive data with certain actions without prompting the user. This is due to errors in handling permissions. The vulnerability could allow attackers to access sensitive information without user consent on older iOS, iPadOS, macOS, and watchOS devices.
Recommendations:
Update to macOS Sonoma 14.3 or later
Update to watchOS 10.3 or later
Update to iOS 17.3 or later
Update to iPadOS 17.3 or later
As a temporary workaround, consider disabling the use of shortcuts that may utilize sensitive data without user consent until a patch is applied.
Avoid opening shortcuts from unknown users and be cautious when clicking on links in applications.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Shortcuts
Apple Macos
Ios
Ipados
Watchos