Lucene search

K
nvd[email protected]NVD:CVE-2024-40787
HistoryJul 29, 2024 - 11:15 p.m.

CVE-2024-40787

2024-07-2923:15:12
web.nvd.nist.gov
5
cve-2024-40787
user consent prompt
macos ventura 13.6.8
macos monterey 12.7.6
ios 17.6
ipados 17.6
watchos 10.6
macos sonoma 14.6
internet permission bypass

CVSS3

7.1

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N

EPSS

0.001

Percentile

17.1%

This issue was addressed by adding an additional prompt for user consent. This issue is fixed in macOS Ventura 13.6.8, macOS Monterey 12.7.6, iOS 17.6 and iPadOS 17.6, watchOS 10.6, macOS Sonoma 14.6. A shortcut may be able to bypass Internet permission requirements.

Affected configurations

Nvd
Node
appleipadosRange<17.6
OR
appleiphone_osRange<17.6
OR
applemacosRange<12.7.6
OR
applemacosRange13.013.6.8
OR
applemacosRange14.014.6
OR
applewatchosRange<10.6
VendorProductVersionCPE
appleipados*cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*
appleiphone_os*cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*
applemacos*cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
applewatchos*cpe:2.3:o:apple:watchos:*:*:*:*:*:*:*:*

CVSS3

7.1

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N

EPSS

0.001

Percentile

17.1%