First published: Mon Sep 16 2024(Updated: )
This issue was addressed through improved state management. This issue is fixed in iOS 17.7 and iPadOS 17.7, iOS 18 and iPadOS 18, watchOS 11. An attacker with physical access to a locked device may be able to Control Nearby Devices via accessibility features.
Credit: product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
Apple iPadOS | <17.7 | |
Apple iPhone OS | <17.7 | |
Apple watchOS | <11.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-44171 is considered a high severity vulnerability that could allow an attacker with physical access to control nearby devices.
To fix CVE-2024-44171, update to iOS 17.7, iPadOS 17.7, iOS 18, iPadOS 18, or watchOS 11.
CVE-2024-44171 affects iPadOS versions prior to 17.7, iPhone OS versions prior to 17.7, and watchOS versions prior to 11.0.
No, CVE-2024-44171 requires physical access to the locked device to exploit.
CVE-2024-44171 involves insufficient state management that may allow control of nearby devices through accessibility features.