First published: Tue Mar 05 2024(Updated: )
Accessibility. A privacy issue was addressed with improved private data redaction for log entries.
Credit: CVE-2024-23220 Deutsche Telekom Security GmbH sponsored by Bundesamt für Sicherheit in der Informationstechnik Pwn2car James Lee @Windowsrcer Johan Carlsson (joaxcar) Georg Felber Marco Squarcina Meysam Firouzi @R00tkitsmm Trend Micro Zero Day InitiativePatrick Reardon CVE-2024-23296 Junsung Lee Trend Micro Zero Day InitiativeAmir Bazine CrowdStrike Counter Adversary OperationsKarsten König CrowdStrike Counter Adversary OperationsDohyun Lee @l33d0hyun Lyutoon Mr.R CVE-2024-23235 Xinru Chi Pangu LabCVE-2024-23225 Zhenjiang Zhao pangu teamQianxin CrowdStrike Counter Adversary Operations CrowdStrike Counter Adversary OperationsGuilherme Rambo Best Buddy Apps product-security@apple.com an anonymous researcher ali yabuz scj643 Kirin @Pwnrin Harsh Tyagi Lyra Rebane (rebane2001) Om Kothawade Matej Rabzelj Mickey Jin @patch1t Wojciech Regula SecuRingluckyu @uuulucky K宝 Fudan UniversityLFY @secsys Fudan UniversityLewis Hardy Bistrit Dahal CVE-2024-23241 CVE-2024-23242 CVE-2024-23205 CVE-2022-48554 CVE-2024-23291 Marc Newlin SkySafeCristian Dinca Computer ScienceRomania anbu1024 SecANT
Affected Software | Affected Version | How to fix |
---|---|---|
Apple iOS, iPadOS, and watchOS | <17.4 | 17.4 |
Apple iOS, iPadOS, and watchOS | <17.4 | 17.4 |
visionOS | <1.1 | 1.1 |
iPadOS | <17.4 | |
iStyle @cosme iPhone OS | <17.4 | |
visionOS | <1.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Appears in the following advisories)
(Found alongside the following vulnerabilities)
CVE-2024-23220 is classified as a high severity vulnerability affecting Safari that allows user fingerprinting.
To fix CVE-2024-23220, update to visionOS 1.1, iOS 17.4, or iPadOS 17.4.
CVE-2024-23220 affects versions of visionOS prior to 1.1 and iOS/iPadOS prior to 17.4.
CVE-2024-23220 describes a vulnerability where apps may be able to fingerprint users due to cache handling.
The affected products that need to be updated for CVE-2024-23220 include Apple visionOS, iOS, and iPadOS.