VulnerabilityModified
CVE-2024-40813
An attacker with physical access may be able to use Siri to access sensitive user data.
MEDIUM 4.6EPSS 0.36%
Does this matter?
Lower severity and a low EPSS score (0.36%). Track it; it rarely justifies an emergency change on its own.
Description
A lock screen issue was addressed with improved state management. This issue is fixed in iOS 17.6 and iPadOS 17.6, watchOS 10.6. An attacker with physical access may be able to use Siri to access sensitive user data.
- CVSS 3.1
- 4.6 MEDIUMCVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 0.36% probability · 30th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-922
- Affected
- apple/ipados · apple/iphone os · apple/watchos
- Source
- product-security@apple.com
References
- https://support.apple.com/en-us/120909
- https://support.apple.com/en-us/120916
- http://seclists.org/fulldisclosure/2024/Jul/16Mailing List, Third Party Advisory
- http://seclists.org/fulldisclosure/2024/Jul/21Mailing List, Third Party Advisory
- https://support.apple.com/en-us/HT214117Release Notes, Vendor Advisory
- https://support.apple.com/en-us/HT214124Release Notes, Vendor Advisory
- https://support.apple.com/kb/HT214117
- https://support.apple.com/kb/HT214124
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.