This issue was addressed through improved state management. This issue is fixed in tvOS 17.4, iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4. An app may be able to leak sensitive user information.
References
| Link | Resource |
|---|---|
| http://seclists.org/fulldisclosure/2024/Mar/21 | Mailing List |
| http://seclists.org/fulldisclosure/2024/Mar/25 | Mailing List |
| https://support.apple.com/en-us/HT214081 | Vendor Advisory |
| https://support.apple.com/en-us/HT214084 | Vendor Advisory |
| https://support.apple.com/en-us/HT214086 | Vendor Advisory |
| http://seclists.org/fulldisclosure/2024/Mar/21 | Mailing List |
| http://seclists.org/fulldisclosure/2024/Mar/25 | Mailing List |
| https://support.apple.com/en-us/HT214081 | Vendor Advisory |
| https://support.apple.com/en-us/HT214084 | Vendor Advisory |
| https://support.apple.com/en-us/HT214086 | Vendor Advisory |
| https://support.apple.com/kb/HT214081 | |
| https://support.apple.com/kb/HT214084 | |
| https://support.apple.com/kb/HT214086 |
Configurations
Configuration 1 (hide)
|
History
04 Nov 2025, 19:16
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
06 Dec 2024, 02:19
| Type | Values Removed | Values Added |
|---|---|---|
| References | () http://seclists.org/fulldisclosure/2024/Mar/21 - Mailing List | |
| References | () http://seclists.org/fulldisclosure/2024/Mar/25 - Mailing List | |
| References | () https://support.apple.com/en-us/HT214081 - Vendor Advisory | |
| References | () https://support.apple.com/en-us/HT214084 - Vendor Advisory | |
| References | () https://support.apple.com/en-us/HT214086 - Vendor Advisory | |
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 5.5 |
| First Time |
Apple iphone Os
Apple Apple ipad Os Apple tvos Apple macos |
|
| CPE | cpe:2.3:o:apple:ipad_os:*:*:*:*:*:*:*:* cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:* cpe:2.3:o:apple:tvos:*:*:*:*:*:*:*:* cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:* |
|
| CWE | NVD-CWE-noinfo |
Information
Published : 2024-03-08 02:15
Updated : 2025-11-04 19:16
NVD link : CVE-2024-23241
Mitre link : CVE-2024-23241
CVE.ORG link : CVE-2024-23241
JSON object : View
Products Affected
apple
- macos
- iphone_os
- ipad_os
- tvos
CWE
