First published: Tue Mar 05 2024(Updated: )
Accessibility. A privacy issue was addressed with improved private data redaction for log entries.
Credit: Guilherme Rambo Best Buddy Apps product-security@apple.com m4yfly with TianGong Team Legendsec at Qi'anxin Groupan anonymous researcher Csaba Fitzl @theevilbit OffSecCVE-2024-23205 CVE-2022-48554 Joshua Jewett @JoshJewett33 Mickey Jin @patch1t Junsung Lee Trend Micro Zero Day InitiativeZhenjiang Zhao pangu teamQianxin CrowdStrike Counter Adversary Operations CrowdStrike Counter Adversary OperationsAmir Bazine CrowdStrike Counter Adversary OperationsKarsten König CrowdStrike Counter Adversary OperationsDohyun Lee @l33d0hyun Lyutoon Mr.R Murray Mike Pedro Tôrres @t0rr3sp3dr0 CVE-2024-23235 Xinru Chi Pangu LabCVE-2024-23225 koocola ali yabuz Kirin @Pwnrin Meysam Firouzi @R00tkitsmm Trend Micro Zero Day Initiative @08Tc3wBB JamfCVE-2024-23283 CVE-2023-48795 CVE-2023-51384 CVE-2023-51385 Bohdan Stasiuk @Bohdan_Stasiuk Harsh Tyagi Wojciech Regula SecuRingCVE-2024-23296 Lyra Rebane (rebane2001) Matej Rabzelj CVE-2024-23238 Yiğit Can YILMAZ @yilmazcanyigit luckyu @uuulucky K宝 Fudan UniversityLFY @secsys Fudan UniversityLewis Hardy Bistrit Dahal CVE-2024-23241 CVE-2024-23242 Matthew Loewen Deutsche Telekom Security GmbH sponsored by Bundesamt für Sicherheit in der Informationstechnik anbu1024 SecANTPwn2car James Lee @Windowsrcer Johan Carlsson (joaxcar) Georg Felber Marco Squarcina Marc Newlin SkySafeBrian McNulty Stephan Casas CVE-2024-23291 scj643 CVE-2024-23220 Om Kothawade Cristian Dinca Computer ScienceRomania
Affected Software | Affected Version | How to fix |
---|---|---|
Apple macOS | <14.4 | 14.4 |
watchOS | <10.4 | 10.4 |
tvOS | <17.4 | 17.4 |
iPadOS | <17.4 | |
Apple iPhone OS | <17.4 | |
Apple macOS | >=14.0<14.4 | |
tvOS | <17.4 | |
watchOS | <10.4 | |
Apple iOS | <17.4 | 17.4 |
iPadOS | <17.4 | 17.4 |
<10.4 | 10.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Appears in the following advisories)
(Found alongside the following vulnerabilities)
CVE-2024-23250 is classified as a moderate severity vulnerability due to improper access restrictions.
To fix CVE-2024-23250, update your Apple devices to tvOS 17.4, iOS 17.4, iPadOS 17.4, macOS Sonoma 14.4, or watchOS 10.4.
CVE-2024-23250 affects devices running tvOS, iOS, iPadOS, macOS, and watchOS prior to their respective fixed versions.
CVE-2024-23250 may allow an app to access Bluetooth-connected microphones without user permission.
CVE-2024-23250 was disclosed in March 2024, prompting the need for updates to secure affected products.