CVE-2024-23275
CVE-2024-23275
Vexday Risk Score
13Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 4.7EPSS 0.2%KEV nãoPoC —Nuclei —Metasploit —Patch —
Lifecycle
08 Mar 2024Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
A race condition was addressed with additional validation. This issue is fixed in macOS Monterey 12.7.4, macOS Sonoma 14.4, macOS Ventura 13.6.5. An app may be able to access protected user data.
CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N
Affected products
Apple · macOSWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →References
http://seclists.org/fulldisclosure/2024/Mar/21http://seclists.org/fulldisclosure/2024/Mar/22http://seclists.org/fulldisclosure/2024/Mar/23https://support.apple.com/en-us/120884https://support.apple.com/en-us/120886https://support.apple.com/en-us/120895https://support.apple.com/en-us/HT214083https://support.apple.com/en-us/HT214084https://support.apple.com/en-us/HT214085https://support.apple.com/kb/HT214083https://support.apple.com/kb/HT214084https://support.apple.com/kb/HT214085