PT-2024-3896 · Apple · Ipados+4

H33Tjubaer

+1

·

Published

2024-01-22

·

Updated

2026-03-05

·

CVE-2024-23204

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions: macOS Sonoma versions prior to 14.3 watchOS versions prior to 10.3 iOS versions prior to 17.3 iPadOS versions prior to 17.3
Description: The issue is related to the Apple Shortcuts app, where a shortcut may be able to use sensitive data with certain actions without prompting the user. This is due to errors in handling permissions. The vulnerability could allow attackers to access sensitive information without user consent on older iOS, iPadOS, macOS, and watchOS devices.
Recommendations: Update to macOS Sonoma 14.3 or later Update to watchOS 10.3 or later Update to iOS 17.3 or later Update to iPadOS 17.3 or later As a temporary workaround, consider disabling the use of shortcuts that may utilize sensitive data without user consent until a patch is applied. Avoid opening shortcuts from unknown users and be cautious when clicking on links in applications.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2024-04303
CVE-2024-23204

Affected Products

Shortcuts
Apple Macos
Ios
Ipados
Watchos