First published: Mon Sep 16 2024(Updated: )
Accessibility. This issue was addressed by restricting options offered on a locked device.
Credit: product-security@apple.com Abhay Kailasia @abhay_kailasia Lakshmi Narain College of Technology Bhopal IndiaChloe Surett Jake Derouin Abhay Kailasia @abhay_kailasia Lakshmi Narain College of Technology Bhopal IndiaHolger Fuhrmannek Tuan D. Hoang Snoolie Keffaber @0xilis an anonymous researcher Daniele Antonioli @08Tc3wBB JamfDenis Tokarev @illusionofcha0s Junsung Lee dw0r ZeroPointer Lab working with Trend Micro Zero Day Initiativean anonymous researcher Antonio Zekić Andrew Lytvynov Alexander Heinrich SEEMOO DistriNet KU Leuven @vanhoefm TU Darmstadt @Sn0wfreeze Mathy Vanhoef OSS-Fuzz Google Project ZeroNed Williamson Google Project ZeroRodolphe BRUNETTI @eisw0lf Olivier Levon CVE-2023-5841 Alexander Heinrich SEEMOO DistriNet KU Leuven @vanhoefm TU Darmstadt @Sn0wfreeze Mathy Vanhoef ajajfxhj Bistrit Dahal an anonymous researcher Joshua Keller an anonymous researcher Narendra Bhati Cyber Security at Suma Soft PvtManager Cyber Security at Suma Soft PvtPune (India) Kenneth Chew Anamika Adhikari Csaba Fitzl @theevilbit Kandji냥냥 Wojciech Regula SecuRingOm Kothawade Zaprico DigitalOmar A. Alanis the UNTHSC College of PharmacyChi Yuan Chang ZUSO ARTtaikosoup Srijan Poudel Bistrit Dahal K宝 LFY @secsys Smi1e yulige Cristian Dinca (icmd.tech) Rodolphe BRUNETTI @eisw0lf Bohdan Stasiuk @Bohdan_Stasiuk Justin Cohen Ron Masas Narendra Bhati Cyber Security at Suma Soft PvtManager Cyber Security at Suma Soft PvtPune (India) Domien Schepers Chloe Surett Jake Derouin Abhay Kailasia @abhay_kailasia Lakshmi Narain College of Technology Bhopal IndiaHolger Fuhrmannek Tuan D. Hoang Snoolie Keffaber @0xilis an anonymous researcher Daniele Antonioli @08Tc3wBB JamfDenis Tokarev @illusionofcha0s Junsung Lee dw0r ZeroPointer Lab working with Trend Micro Zero Day Initiativean anonymous researcher Antonio Zekić Andrew Lytvynov Alexander Heinrich SEEMOO DistriNet KU Leuven @vanhoefm TU Darmstadt @Sn0wfreeze Mathy Vanhoef OSS-Fuzz Google Project ZeroNed Williamson Google Project ZeroRodolphe BRUNETTI @eisw0lf Olivier Levon CVE-2023-5841 Alexander Heinrich SEEMOO DistriNet KU Leuven @vanhoefm TU Darmstadt @Sn0wfreeze Mathy Vanhoef ajajfxhj Bistrit Dahal an anonymous researcher Joshua Keller an anonymous researcher Narendra Bhati Cyber Security at Suma Soft PvtManager Cyber Security at Suma Soft PvtPune (India) Kenneth Chew Anamika Adhikari Csaba Fitzl @theevilbit Kandji냥냥 Wojciech Regula SecuRingOm Kothawade Zaprico DigitalOmar A. Alanis the UNTHSC College of PharmacyChi Yuan Chang ZUSO ARTtaikosoup Srijan Poudel Bistrit Dahal K宝 LFY @secsys Smi1e yulige Cristian Dinca (icmd.tech) Rodolphe BRUNETTI @eisw0lf Bohdan Stasiuk @Bohdan_Stasiuk Justin Cohen Ron Masas Narendra Bhati Cyber Security at Suma Soft PvtManager Cyber Security at Suma Soft PvtPune (India) Domien Schepers Jake Derouin Abhay Kailasia @abhay_kailasia Lakshmi Narain College of Technology Bhopal IndiaHolger Fuhrmannek Tuan D. Hoang Snoolie Keffaber @0xilis an anonymous researcher Daniele Antonioli @08Tc3wBB JamfDenis Tokarev @illusionofcha0s Junsung Lee dw0r ZeroPointer Lab working with Trend Micro Zero Day Initiativean anonymous researcher Antonio Zekić Andrew Lytvynov Alexander Heinrich SEEMOO DistriNet KU Leuven @vanhoefm TU Darmstadt @Sn0wfreeze Mathy Vanhoef OSS-Fuzz Google Project ZeroNed Williamson Google Project ZeroRodolphe BRUNETTI @eisw0lf Olivier Levon CVE-2023-5841 Alexander Heinrich SEEMOO DistriNet KU Leuven @vanhoefm TU Darmstadt @Sn0wfreeze Mathy Vanhoef ajajfxhj Bistrit Dahal an anonymous researcher Joshua Keller an anonymous researcher Narendra Bhati Cyber Security at Suma Soft PvtManager Cyber Security at Suma Soft PvtPune (India) Kenneth Chew Anamika Adhikari Csaba Fitzl @theevilbit Kandji냥냥 Wojciech Regula SecuRingOm Kothawade Zaprico DigitalOmar A. Alanis the UNTHSC College of PharmacyChi Yuan Chang ZUSO ARTtaikosoup Srijan Poudel Bistrit Dahal K宝 LFY @secsys Smi1e yulige Cristian Dinca (icmd.tech) Rodolphe BRUNETTI @eisw0lf Bohdan Stasiuk @Bohdan_Stasiuk Justin Cohen Ron Masas Narendra Bhati Cyber Security at Suma Soft PvtManager Cyber Security at Suma Soft PvtPune (India) Domien Schepers Abhay Kailasia @abhay_kailasia Lakshmi Narain College of Technology Bhopal IndiaHolger Fuhrmannek Tuan D. Hoang Snoolie Keffaber @0xilis an anonymous researcher Daniele Antonioli @08Tc3wBB JamfDenis Tokarev @illusionofcha0s Junsung Lee dw0r ZeroPointer Lab working with Trend Micro Zero Day Initiativean anonymous researcher Antonio Zekić Andrew Lytvynov Alexander Heinrich SEEMOO DistriNet KU Leuven @vanhoefm TU Darmstadt @Sn0wfreeze Mathy Vanhoef OSS-Fuzz Google Project ZeroNed Williamson Google Project ZeroRodolphe BRUNETTI @eisw0lf Olivier Levon CVE-2023-5841 Alexander Heinrich SEEMOO DistriNet KU Leuven @vanhoefm TU Darmstadt @Sn0wfreeze Mathy Vanhoef ajajfxhj Bistrit Dahal an anonymous researcher Joshua Keller an anonymous researcher Narendra Bhati Cyber Security at Suma Soft PvtManager Cyber Security at Suma Soft PvtPune (India) Kenneth Chew Anamika Adhikari Csaba Fitzl @theevilbit Kandji냥냥 Wojciech Regula SecuRingOm Kothawade Zaprico DigitalOmar A. Alanis the UNTHSC College of PharmacyChi Yuan Chang ZUSO ARTtaikosoup Srijan Poudel Bistrit Dahal K宝 LFY @secsys Smi1e yulige Cristian Dinca (icmd.tech) Rodolphe BRUNETTI @eisw0lf Bohdan Stasiuk @Bohdan_Stasiuk Justin Cohen Ron Masas Narendra Bhati Cyber Security at Suma Soft PvtManager Cyber Security at Suma Soft PvtPune (India) Domien Schepers
Affected Software | Affected Version | How to fix |
---|---|---|
Apple iPadOS | <18.0 | |
Apple iPhone OS | <18.0 | |
<18 | 18 | |
<18 | 18 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2024-40852 has been classified with a severity that indicates potential risks associated with accessibility features in Apple devices.
To fix CVE-2024-40852, users should update their Apple iOS or iPadOS to version 18 or later.
CVE-2024-40852 affects Apple devices running iOS and iPadOS versions prior to 18.0.
CVE-2024-40852 addresses accessibility vulnerabilities that could affect data protection and state management.
Yes, CVE-2024-40852 is related to device security by addressing potential risks when using accessibility options on locked devices.