First published: Tue Mar 05 2024(Updated: )
Accessibility. A privacy issue was addressed with improved private data redaction for log entries.
Credit: CVE-2024-23241 product-security@apple.com Junsung Lee Trend Micro Zero Day InitiativeAmir Bazine CrowdStrike Counter Adversary OperationsKarsten König CrowdStrike Counter Adversary OperationsDohyun Lee @l33d0hyun Lyutoon Mr.R CVE-2024-23235 Xinru Chi Pangu LabCVE-2024-23225 an anonymous researcher ali yabuz scj643 Meysam Firouzi @R00tkitsmm Trend Micro Zero Day InitiativeCVE-2024-23296 Mickey Jin @patch1t Wojciech Regula SecuRingBistrit Dahal Deutsche Telekom Security GmbH sponsored by Bundesamt für Sicherheit in der Informationstechnik Pwn2car James Lee @Windowsrcer Johan Carlsson (joaxcar) Georg Felber Marco Squarcina Guilherme Rambo Best Buddy AppsCVE-2022-48554 CVE-2024-23291 Kirin @Pwnrin Marc Newlin SkySafeCVE-2024-23205 Harsh Tyagi CVE-2024-23220 Lyra Rebane (rebane2001) Om Kothawade Matej Rabzelj luckyu @uuulucky K宝 Fudan UniversityLFY @secsys Fudan UniversityLewis Hardy CVE-2024-23242 Cristian Dinca Computer ScienceRomania koocola @08Tc3wBB JamfCVE-2024-23283 CVE-2023-48795 CVE-2023-51384 CVE-2023-51385 Pedro Tôrres @t0rr3sp3dr0 Bohdan Stasiuk @Bohdan_Stasiuk CVE-2024-23238 Yiğit Can YILMAZ @yilmazcanyigit Joshua Jewett @JoshJewett33 Matthew Loewen m4yfly with TianGong Team Legendsec at Qi'anxin GroupCsaba Fitzl @theevilbit OffSecZhenjiang Zhao pangu teamQianxin CrowdStrike Counter Adversary Operations CrowdStrike Counter Adversary OperationsMurray Mike Stephan Casas Brian McNulty
Affected Software | Affected Version | How to fix |
---|---|---|
Apple macOS | <14.4 | 14.4 |
tvOS | <17.4 | 17.4 |
iPadOS | <17.4 | |
Apple iPhone OS | <17.4 | |
Apple macOS | >=14.0<14.4 | |
tvOS | <17.4 | |
Apple iOS | <17.4 | 17.4 |
iPadOS | <17.4 | 17.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Appears in the following advisories)
(Found alongside the following vulnerabilities)
CVE-2024-23241 is a vulnerability that may allow an app to leak sensitive user information.
To fix CVE-2024-23241, update your device to tvOS 17.4, iOS 17.4, iPadOS 17.4, or macOS Sonoma 14.4.
CVE-2024-23241 affects Apple tvOS, iOS, iPadOS, and macOS versions prior to their respective 17.4 and 14.4 releases.
CVE-2024-23241 allows potential leakage of sensitive user information through certain applications.
CVE-2024-23241 was addressed through improved state management to enhance user privacy and security.