VulnerabilityModified
CVE-2024-23261
An attacker may be able to read information belonging to another user.
HIGH 7.5EPSS 0.91%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.91%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
A logic issue was addressed with improved state management. This issue is fixed in macOS Monterey 12.7.6, macOS Sonoma 14.4, macOS Ventura 13.6.8. An attacker may be able to read information belonging to another user.
- CVSS 3.1
- 7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 0.91% probability · 58th percentile
- CISA KEV
- Not listed
- Affected
- apple/macos
- Source
- product-security@apple.com
References
- https://support.apple.com/en-us/120895
- https://support.apple.com/en-us/120910
- https://support.apple.com/en-us/120912
- http://seclists.org/fulldisclosure/2024/Jul/19Mailing List, Third Party Advisory
- http://seclists.org/fulldisclosure/2024/Jul/20Mailing List, Third Party Advisory
- https://support.apple.com/en-us/HT214084Release Notes, Vendor Advisory
- https://support.apple.com/en-us/HT214118Release Notes, Vendor Advisory
- https://support.apple.com/en-us/HT214120Release Notes, Vendor Advisory
- https://support.apple.com/kb/HT214084Release Notes, Vendor Advisory
- https://support.apple.com/kb/HT214118
- https://support.apple.com/kb/HT214120
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.