First published: Mon Sep 16 2024(Updated: )
Accessibility. This issue was addressed through improved state management.
Credit: Jake Derouin (jakederouin.com) Denis Tokarev @illusionofcha0s Junsung Lee dw0r ZeroPointer Lab working with Trend Micro Zero Day Initiativean anonymous researcher Antonio Zekić Alexander Heinrich SEEMOO DistriNet KU Leuven @vanhoefm TU Darmstadt @Sn0wfreeze Mathy Vanhoef Kirin @Pwnrin Jeff Johnson (underpassapp.com) OSS-Fuzz Google Project ZeroNed Williamson Google Project ZeroOlivier Levon Narendra Bhati Cyber Security at Suma Soft PvtManager Cyber Security at Suma Soft PvtPune (India) 냥냥 K宝 LFY @secsys Smi1e yulige Cristian Dinca (icmd.tech) Rodolphe BRUNETTI @eisw0lf Narendra Bhati Cyber Security At Suma Soft PvtManager Cyber Security At Suma Soft PvtTashita Software Security Ron Masas Chloe Surett Abhay Kailasia @abhay_kailasia Lakshmi Narain College of Technology Bhopal IndiaHolger Fuhrmannek Tuan D. Hoang Snoolie Keffaber @0xilis Daniele Antonioli Csaba Fitzl @theevilbit Kandji @08Tc3wBB JamfAndrew Lytvynov CVE-2023-5841 ajajfxhj Bistrit Dahal Joshua Keller Lukas Kenneth Chew Anamika Adhikari Wojciech Regula SecuRingOm Kothawade Zaprico DigitalOmar A. Alanis the UNTHSC College of PharmacyMatej Moravec @MacejkoMoravec Chi Yuan Chang ZUSO ARTtaikosoup Srijan Poudel Ron Masas BreakPointBohdan Stasiuk @Bohdan_Stasiuk Justin Cohen Tim Michaud @TimGMichaud MoveworksPreet Dsouza (Fleming College Computer Security & Investigations Program) Domien Schepers Kirin @Pwnrin NorthSealuckyu @uuulucky NorthSeaMickey Jin @patch1t product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
Apple iOS, iPadOS, and watchOS | <11 | 11 |
Apple iOS and iPadOS | <18 | 18 |
Apple iOS, iPadOS, and macOS | <18 | 18 |
Apple iOS and iPadOS | <17.7 | 17.7 |
Apple iOS, iPadOS, and macOS | <17.7 | 17.7 |
Apple iOS, iPadOS, and macOS | <17.7 | |
iPhone OS | <17.7 | |
Apple iOS, iPadOS, and watchOS | <11.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2024-44171 is considered a high severity vulnerability that could allow an attacker with physical access to control nearby devices.
To fix CVE-2024-44171, update to iOS 17.7, iPadOS 17.7, iOS 18, iPadOS 18, or watchOS 11.
CVE-2024-44171 affects iPadOS versions prior to 17.7, iPhone OS versions prior to 17.7, and watchOS versions prior to 11.0.
No, CVE-2024-44171 requires physical access to the locked device to exploit.
CVE-2024-44171 involves insufficient state management that may allow control of nearby devices through accessibility features.