Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2024-44255


A path handling issue was addressed with improved logic. This issue is fixed in visionOS 2.1, iOS 18.1 and iPadOS 18.1, macOS Ventura 13.7.1, macOS Sonoma 14.7.1, watchOS 11.1, tvOS 18.1. A malicious app may be able to run arbitrary shortcuts without user consent.


Published

2024-10-28T21:15:07.003

Last Modified

2025-11-03T22:18:33.050

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 7.8 (HIGH)

Weaknesses
  • Type: Primary
    CWE-22
  • Type: Secondary
    CWE-22

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System apple ipados < 18.1 Yes
Operating System apple iphone_os < 18.1 Yes
Operating System apple macos < 13.7.1 Yes
Operating System apple macos < 14.7.1 Yes
Operating System apple tvos < 18.1 Yes
Operating System apple visionos < 2.1 Yes
Operating System apple watchos < 11.1 Yes

References