CVE-2024-40836
EUVD-2024-3867429.07.2024, 23:15
A logic issue was addressed with improved checks. This issue is fixed in iOS 16.7.9 and iPadOS 16.7.9, iOS 17.6 and iPadOS 17.6, macOS Sonoma 14.6, watchOS 10.6. A shortcut may be able to use sensitive data with certain actions without prompting the user.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| apple | ipados | 𝑥 < 16.7.9 |
| apple | ipados | 17.0 ≤ 𝑥 < 17.6 |
| apple | iphone_os | 𝑥 < 16.7.9 |
| apple | iphone_os | 17.0 ≤ 𝑥 < 17.6 |
| apple | macos | 14.0 ≤ 𝑥 < 14.6 |
| apple | watchos | 𝑥 < 10.6 |
𝑥
= Vulnerable software versions
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| apple | watchos | 𝑥 < 10.6 | ADP |
| apple | macos | 𝑥 < 14.6 | ADP |
| apple | ipad_os | 𝑥 < 16.7.9 | ADP |
| apple | iphone_os | 𝑥 < 16.7.9 | ADP |
| apple | iphone_os | 17.0 ≤ 𝑥 < 17.6 | ADP |
| apple | ipad_os | 17.0 ≤ 𝑥 < 17.6 | ADP |
Common Weakness Enumeration
References