VulnerabilityModified
CVE-2024-0230
An attacker with physical access to the accessory may be able to extract its Bluetooth pairing key and monitor Bluetooth traffic.
LOW 2.4EPSS 1.22%
Does this matter?
Lower severity and a low EPSS score (1.22%). Track it; it rarely justifies an emergency change on its own.
Description
A session management issue was addressed with improved checks. This issue is fixed in Magic Keyboard Firmware Update 2.0.6. An attacker with physical access to the accessory may be able to extract its Bluetooth pairing key and monitor Bluetooth traffic.
- CVSS 3.1
- 2.4 LOWCVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
- EPSS
- 1.22% probability · 67th percentile
- CISA KEV
- Not listed
- Affected
- apple/magic keyboard firmware
- Source
- product-security@apple.com
References
- https://support.apple.com/en-us/120303
- https://support.apple.com/en-us/HT214050Release Notes, Third Party Advisory
- https://support.apple.com/kb/HT214050
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.