First published: Tue Mar 05 2024(Updated: )
A lock screen issue was addressed with improved state management. This issue is fixed in iOS 16.7.6 and iPadOS 16.7.6, iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4, watchOS 10.4. A person with physical access to a device may be able to use Siri to access private calendar information.
Credit: Lewis Hardy product-security@apple.com Kirin @Pwnrin luckyu @uuulucky Mickey Jin @patch1t an anonymous researcher K宝 Fudan UniversityLFY @secsys Fudan UniversityBistrit Dahal CVE-2024-23241 CVE-2024-23242 Joshua Jewett @JoshJewett33 Matthew Loewen Deutsche Telekom Security GmbH sponsored by Bundesamt für Sicherheit in der Informationstechnik anbu1024 SecANTPwn2car James Lee @Windowsrcer Johan Carlsson (joaxcar) Georg Felber Marco Squarcina CVE-2024-23238 Wojciech Regula SecuRingYiğit Can YILMAZ @yilmazcanyigit Lyra Rebane (rebane2001) Matej Rabzelj CVE-2024-23225 koocola ali yabuz Meysam Firouzi @R00tkitsmm Trend Micro Zero Day Initiative @08Tc3wBB JamfCVE-2024-23283 CVE-2023-48795 CVE-2023-51384 CVE-2023-51385 Pedro Tôrres @t0rr3sp3dr0 Bohdan Stasiuk @Bohdan_Stasiuk Harsh Tyagi CVE-2024-23296 Junsung Lee Trend Micro Zero Day InitiativeZhenjiang Zhao pangu teamQianxin CrowdStrike Counter Adversary Operations CrowdStrike Counter Adversary OperationsAmir Bazine CrowdStrike Counter Adversary OperationsKarsten König CrowdStrike Counter Adversary OperationsDohyun Lee @l33d0hyun Lyutoon Mr.R Murray Mike CVE-2024-23235 Xinru Chi Pangu Labm4yfly with TianGong Team Legendsec at Qi'anxin GroupGuilherme Rambo Best Buddy AppsCsaba Fitzl @theevilbit OffSecCVE-2024-23205 CVE-2022-48554 Marc Newlin SkySafeBrian McNulty Stephan Casas CVE-2024-23291 Meng Zhang (鲸落) NorthSeaJubaer Alnazi @h33tjubaer Clemens Lang scj643 CVE-2024-23220 Om Kothawade Cristian Dinca Computer ScienceRomania
Affected Software | Affected Version | How to fix |
---|---|---|
Apple macOS | <14.4 | 14.4 |
<14.4 | 14.4 | |
Apple iOS, iPadOS, and watchOS | <16.7.6 | |
Apple iOS, iPadOS, and watchOS | >=17.0<17.4 | |
iOS | <16.7.6 | |
iOS | >=17.0<17.4 | |
Apple iOS and macOS | >=14.0<14.4 | |
Apple iOS, iPadOS, and watchOS | <10.4 | |
Apple iOS, iPadOS, and watchOS | <10.4 | 10.4 |
Apple iOS, iPadOS, and watchOS | <16.7.6 | 16.7.6 |
Apple iOS, iPadOS, and watchOS | <16.7.6 | 16.7.6 |
Apple iOS, iPadOS, and watchOS | <17.4 | 17.4 |
Apple iOS, iPadOS, and watchOS | <17.4 | 17.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Appears in the following advisories)
(Found alongside the following vulnerabilities)
CVE-2024-23289 is considered a medium severity vulnerability due to its potential to expose private calendar information with physical access to the device.
To fix CVE-2024-23289, update your device to iOS 16.7.6, iPadOS 16.7.6, iOS 17.4, iPadOS 17.4, macOS Sonoma 14.4, or watchOS 10.4.
CVE-2024-23289 affects users of Apple devices running iOS, iPadOS, macOS, and watchOS prior to the specified secure versions.
CVE-2024-23289 impacts iPhones, iPads, Macs, and Apple Watches that are running vulnerable versions.
An attacker with physical access to a device may use Siri to gain unauthorized access to private calendar information.