CVE-2024-27855

EUVD-2024-25048
The issue was addressed with improved checks. This issue is fixed in iOS 16.7.8 and iPadOS 16.7.8, iOS 17.5 and iPadOS 17.5, macOS Sonoma 14.5, macOS Ventura 13.6.7. A shortcut may be able to use sensitive data with certain actions without prompting the user.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
8.8 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 63%
Affected Products (NVD)
VendorProductVersion
appleipados
𝑥
< 16.7.8
appleipados
17.0 ≤
𝑥
< 17.5
appleiphone_os
𝑥
< 16.7.8
appleiphone_os
17.0 ≤
𝑥
< 17.5
applemacos
𝑥
< 13.6.7
applemacos
14.0 ≤
𝑥
< 14.5
𝑥
= Vulnerable software versions
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
VendorProductVersionSource
appleiphone_os
𝑥
< 17.5
ADP
appleiphone_os
𝑥
< 16.7.8
ADP
appleipad_os
𝑥
< 17.5
ADP
appleipad_os
𝑥
< 16.7.8
ADP
applemacos
13.0 ≤
𝑥
< 13.6.7
ADP
applemacos
14.0 ≤
𝑥
< 14.5
ADP