PT-2025-3036 · Apple · Ipados+2
Bistrit Dahal
·
Published
2025-01-27
·
Updated
2025-01-28
·
CVE-2024-54512
CVSS v3.1
9.4
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
watchOS versions prior to 11.2
iOS versions prior to 18.2
iPadOS versions prior to 18.2
Description
The issue is related to insufficient protection of service data in the Face Gallery component of watchOS, iOS, and iPadOS operating systems. A system binary could be used to fingerprint a user's Apple Account, potentially allowing a remote attacker to disclose protected information. The problem was solved by removing the relevant flags.
Recommendations
For watchOS versions prior to 11.2, update to watchOS 11.2 to resolve the issue.
For iOS versions prior to 18.2, update to iOS 18.2 to resolve the issue.
For iPadOS versions prior to 18.2, update to iPadOS 18.2 to resolve the issue.
Fix
Incorrect Authorization
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Ios
Ipados
Watchos