8.8

CVE-2024-27855

The issue was addressed with improved checks. This issue is fixed in iOS 16.7.8 and iPadOS 16.7.8, iOS 17.5 and iPadOS 17.5, macOS Sonoma 14.5, macOS Ventura 13.6.7. A shortcut may be able to use sensitive data with certain actions without prompting the user.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Apple ≫ iPadOS Version < 16.7.8
Apple ≫ iPadOS Version >= 17.0 < 17.5
Apple ≫ iPhone OS Version < 16.7.8
Apple ≫ iPhone OS Version >= 17.0 < 17.5
Apple ≫ macOS Version < 13.6.7
Apple ≫ macOS Version >= 14.0 < 14.5
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.72% 0.49
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 8.8 2.8 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CISA-ADP 8.8 2.8 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CWE-284 Improper Access Control

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

https://support.apple.com/kb/HT214107
Vendor Advisory
https://support.apple.com/kb/HT214100
Vendor Advisory
https://support.apple.com/kb/HT214101
Vendor Advisory
https://support.apple.com/kb/HT214106
Vendor Advisory
https://support.apple.com/en-us/HT214106
Vendor Advisory
https://support.apple.com/en-us/HT214100
Vendor Advisory
https://support.apple.com/en-us/HT214107
Vendor Advisory
https://support.apple.com/en-us/HT214101
Vendor Advisory
https://support.apple.com/en-us/120898
https://support.apple.com/en-us/120903
https://support.apple.com/en-us/120905
https://support.apple.com/en-us/120900