PT-2025-3036 · Apple · Ipados+2

Bistrit Dahal

·

Published

2025-01-27

·

Updated

2025-01-28

·

CVE-2024-54512

CVSS v3.1

9.4

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions watchOS versions prior to 11.2 iOS versions prior to 18.2 iPadOS versions prior to 18.2
Description The issue is related to insufficient protection of service data in the Face Gallery component of watchOS, iOS, and iPadOS operating systems. A system binary could be used to fingerprint a user's Apple Account, potentially allowing a remote attacker to disclose protected information. The problem was solved by removing the relevant flags.
Recommendations For watchOS versions prior to 11.2, update to watchOS 11.2 to resolve the issue. For iOS versions prior to 18.2, update to iOS 18.2 to resolve the issue. For iPadOS versions prior to 18.2, update to iPadOS 18.2 to resolve the issue.

Fix

Incorrect Authorization

Information Disclosure

Weakness Enumeration

Related Identifiers

BDU:2025-01493
CVE-2024-54512

Affected Products

Ios
Ipados
Watchos