First published: Tue Mar 05 2024(Updated: )
Accessibility. A privacy issue was addressed with improved private data redaction for log entries.
Credit: K宝 Fudan UniversityLFY @secsys Fudan University product-security@apple.com CVE-2024-23291 Wojciech Regula SecuRingKirin @Pwnrin Marc Newlin SkySafeGuilherme Rambo Best Buddy AppsCVE-2024-23205 CVE-2022-48554 an anonymous researcher Junsung Lee Trend Micro Zero Day InitiativeAmir Bazine CrowdStrike Counter Adversary OperationsKarsten König CrowdStrike Counter Adversary OperationsDohyun Lee @l33d0hyun Lyutoon Mr.R CVE-2024-23225 CVE-2024-23235 Xinru Chi Pangu Labali yabuz scj643 Meysam Firouzi @R00tkitsmm Trend Micro Zero Day InitiativeHarsh Tyagi CVE-2024-23296 CVE-2024-23220 Lyra Rebane (rebane2001) Om Kothawade Matej Rabzelj Mickey Jin @patch1t luckyu @uuulucky Lewis Hardy Bistrit Dahal CVE-2024-23241 CVE-2024-23242 Deutsche Telekom Security GmbH sponsored by Bundesamt für Sicherheit in der Informationstechnik Pwn2car James Lee @Windowsrcer Johan Carlsson (joaxcar) Georg Felber Marco Squarcina Cristian Dinca Computer ScienceRomania koocola @08Tc3wBB JamfCVE-2024-23283 CVE-2023-48795 CVE-2023-51384 CVE-2023-51385 Pedro Tôrres @t0rr3sp3dr0 Bohdan Stasiuk @Bohdan_Stasiuk CVE-2024-23238 Yiğit Can YILMAZ @yilmazcanyigit Joshua Jewett @JoshJewett33 Matthew Loewen m4yfly with TianGong Team Legendsec at Qi'anxin GroupCsaba Fitzl @theevilbit OffSecZhenjiang Zhao pangu teamQianxin CrowdStrike Counter Adversary Operations CrowdStrike Counter Adversary OperationsMurray Mike Stephan Casas Brian McNulty
Affected Software | Affected Version | How to fix |
---|---|---|
Apple macOS | <14.4 | 14.4 |
Apple iOS | <17.4 | 17.4 |
iPadOS | <17.4 | 17.4 |
iPadOS | <17.4 | |
Apple iPhone OS | <17.4 | |
Apple macOS | >=14.0<14.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Appears in the following advisories)
(Found alongside the following vulnerabilities)
CVE-2024-23292 has been classified as a moderate severity vulnerability.
To fix CVE-2024-23292, update your devices to macOS Sonoma 14.4, iOS 17.4, or iPadOS 17.4.
CVE-2024-23292 affects Apple iOS, iPadOS, and macOS versions prior to the specified updates.
CVE-2024-23292 is a data protection vulnerability that may allow unauthorized access to a user's contacts.
CVE-2024-23292 was disclosed in March 2024 as part of Apple's regular security updates.