First published: Mon May 13 2024(Updated: )
A privacy issue was addressed with improved handling of temporary files. This issue is fixed in iOS 17.5 and iPadOS 17.5. An app may be able to access Notes attachments.
Credit: product-security@apple.com Adam Berry Junsung Lee Trend Micro Zero Day InitiativePan ZhenPeng @Peterpan0927 STAR Labs SG Ptepattern-f @pattern_F_ Ant Security Lightan anonymous researcher an anonymous researcher MIT CSAIL MIT CSAILJoseph Ravichandran @0xjprx MIT CSAILPr BarPr Hebrew University EP Nick Wellnhofer Gil Pedersen Dohyun Lee @l33d0hyun LFY @secsys Fudan UniversityTalal Haj Bakry Mysk IncTommy Mysk @mysk_co Mysk IncDaniel Zajork Joshua Zajork Meysam Firouzi @R00tkitsmm Trend Micro Zero Day InitiativeMichael DePlante @izobashi Trend Micro Zero Day InitiativeAndr.Ess Mickey Jin @patch1t Csaba Fitzl @theevilbit KandjiKirin @Pwnrin LFY @secsys 小来来 @Smi1eSEC yulige Snoolie Keffaber @0xilis Robert Reichel Srijan Poudel CVE-2024-27806 Abhay Kailasia @abhay_kailasia Lakshmi Narain College of Technology BhopalRomy R. ajajfxhj Maksymilian Motyl Immunity SystemsManfred Paul @_manfp Trend Micro's Zero Day InitiativeEmilio Cobos MozillaLukas Bernhard CISPA Helmholtz Center for Information SecurityManfred Paul @_manfp Trend Micro Zero Day InitiativeNan Wang @eternalsakura13 360 Vulnerability Research InstituteJoe Rutkowski @Joe12387 Crawless @abrahamjuliot Jeff Johnson underpassappMeysam Firouzi @R00tkitSMM Amir Bazine CrowdStrike Counter Adversary OperationsKarsten König CrowdStrike Counter Adversary OperationsLucas Monteiro Daniel Monteiro Felipe Monteiro Alexander Heinrich SEEMOO TU Darmstadt @Sn0wfreeze Shai Mishali @freak4pc CertiK SkyFall Team Minghao Lin Baidu Security Baidu SecurityYe Zhang @VAR10CK Baidu Security
Affected Software | Affected Version | How to fix |
---|---|---|
Apple iOS, iPadOS, and watchOS | <17.5 | 17.5 |
Apple iOS, iPadOS, and watchOS | <17.5 | 17.5 |
Apple iOS, iPadOS, and watchOS | <17.5 | |
iStyle @cosme iPhone OS | <17.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2024-27845 is categorized as a privacy issue that could potentially lead to unauthorized access to Notes attachments.
To fix CVE-2024-27845, update your Apple device to iOS 17.5 or iPadOS 17.5.
CVE-2024-27845 affects devices running iOS versions prior to 17.5 and iPadOS versions prior to 17.5.
Yes, CVE-2024-27845 may allow apps to access sensitive Notes attachments, leading to potential privacy violations.
CVE-2024-27845 was disclosed as part of Apple's ongoing security updates and addressed in the 17.5 release.