Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2024-40836


A logic issue was addressed with improved checks. This issue is fixed in watchOS 10.6, macOS Sonoma 14.6, iOS 17.6 and iPadOS 17.6, iOS 16.7.9 and iPadOS 16.7.9. A shortcut may be able to use sensitive data with certain actions without prompting the user.


Published

2024-07-29T23:15:14.570

Last Modified

2025-03-13T20:15:21.770

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 5.5 (MEDIUM)

Weaknesses
  • Type: Primary
    NVD-CWE-noinfo
  • Type: Secondary
    CWE-200

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System apple ipados < 16.7.9 Yes
Operating System apple ipados < 17.6 Yes
Operating System apple iphone_os < 16.7.9 Yes
Operating System apple iphone_os < 17.6 Yes
Operating System apple macos < 14.6 Yes
Operating System apple watchos < 10.6 Yes

References