CVE-2024-23282

EUVD-2024-20801
The issue was addressed with improved checks. This issue is fixed in iOS 16.7.8 and iPadOS 16.7.8, iOS 17.5 and iPadOS 17.5, macOS Sonoma 14.5, watchOS 10.5. A maliciously crafted email may be able to initiate FaceTime calls without user authorization.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
5.5 MEDIUM
LOCAL
LOW
NONE
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 3%
Affected Products (NVD)
VendorProductVersion
appleipados
𝑥
< 16.7.8
appleipados
17.0 ≤
𝑥
< 17.5
appleiphone_os
𝑥
< 16.7.8
appleiphone_os
17.0 ≤
𝑥
< 17.5
applemacos
14.0 ≤
𝑥
< 14.5
applewatchos
𝑥
< 10.5
𝑥
= Vulnerable software versions
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
VendorProductVersionSource
appleipados
𝑥
< 16.7.8
ADP
appleipados
17.0 ≤
𝑥
< 17.5
ADP
appleiphone_os
𝑥
< 16.7.8
ADP
appleiphone_os
17.0 ≤
𝑥
< 17.5
ADP
applemacos
14.0 ≤
𝑥
< 14.5
ADP
applewatchos
𝑥
< 10.5
ADP