CVE-2024-54512

The issue was addressed by removing the relevant flags. This issue is fixed in watchOS 11.2, iOS 18.2 and iPadOS 18.2. A system binary could be used to fingerprint a user's Apple Account.
References
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:watchos:*:*:*:*:*:*:*:*

History

04 Feb 2025, 22:15

Type Values Removed Values Added
CWE CWE-863

30 Jan 2025, 17:20

Type Values Removed Values Added
Summary
  • (es) El problema se solucionó eliminando las banderas pertinentes. Este problema se solucionó en watchOS 11.2, iOS 18.2 y iPadOS 18.2. Se podía usar un binario sistema para tomar la huella digital de la cuenta Apple de un usuario.
First Time Apple iphone Os
Apple watchos
Apple
Apple ipados
CWE NVD-CWE-noinfo
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.1
References () https://support.apple.com/en-us/121837 - () https://support.apple.com/en-us/121837 - Release Notes
References () https://support.apple.com/en-us/121843 - () https://support.apple.com/en-us/121843 - Release Notes
CPE cpe:2.3:o:apple:watchos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*

27 Jan 2025, 22:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-01-27 22:15

Updated : 2025-02-04 22:15


NVD link : CVE-2024-54512

Mitre link : CVE-2024-54512

CVE.ORG link : CVE-2024-54512


JSON object : View

Products Affected

apple

  • watchos
  • iphone_os
  • ipados
CWE
NVD-CWE-noinfo CWE-863

Incorrect Authorization