VulnerabilityModified
CVE-2024-23224
The issue was addressed with improved checks.
MEDIUM 5.5EPSS 0.29%
Does this matter?
Lower severity and a low EPSS score (0.29%). Track it; it rarely justifies an emergency change on its own.
Description
The issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14.3, macOS Ventura 13.6.4. An app may be able to access sensitive user data.
- CVSS 3.1
- 5.5 MEDIUMCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
- EPSS
- 0.29% probability · 22th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-200
- Affected
- apple/macos
- Source
- product-security@apple.com
References
- https://support.apple.com/en-us/120307
- https://support.apple.com/en-us/120309
- http://seclists.org/fulldisclosure/2024/Jan/36Third Party Advisory
- http://seclists.org/fulldisclosure/2024/Jan/37Third Party Advisory
- https://support.apple.com/en-us/HT214058Release Notes, Vendor Advisory
- https://support.apple.com/en-us/HT214061Release Notes, Vendor Advisory
- https://support.apple.com/kb/HT214058
- https://support.apple.com/kb/HT214061
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.