7.1

CVE-2024-40774

A downgrade issue was addressed with additional code-signing restrictions. This issue is fixed in iOS 17.6 and iPadOS 17.6, macOS Monterey 12.7.6, macOS Sonoma 14.6, macOS Ventura 13.6.8, tvOS 17.6, watchOS 10.6. An app may be able to bypass Privacy preferences.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
ApplemacOS Version < 12.7.6
ApplemacOS Version >= 13.0 < 13.6.8
ApplemacOS Version >= 14.0 < 14.6
AppleiPhone OS Version < 17.6
AppleiPadOS Version < 17.6
ApplewatchOS Version < 10.6
AppletvOS Version < 17.6
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.02% 0.055
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.1 1.8 5.2
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
134c704f-9b21-4f2e-91b3-4a467353bcc0 5.9 1.5 4
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:N/A:N
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://seclists.org/fulldisclosure/2024/Jul/18
Third Party Advisory
Mailing List
http://seclists.org/fulldisclosure/2024/Jul/16
Third Party Advisory
Mailing List
http://seclists.org/fulldisclosure/2024/Jul/19
Third Party Advisory
Mailing List
http://seclists.org/fulldisclosure/2024/Jul/20
Third Party Advisory
Mailing List
http://seclists.org/fulldisclosure/2024/Jul/21
Third Party Advisory
Mailing List
http://seclists.org/fulldisclosure/2024/Jul/22
Third Party Advisory
Mailing List
https://support.apple.com/en-us/HT214118
Vendor Advisory
Release Notes
https://support.apple.com/en-us/HT214120
Vendor Advisory
Release Notes
https://support.apple.com/en-us/HT214119
Vendor Advisory
Release Notes
https://support.apple.com/en-us/HT214117
Vendor Advisory
Release Notes
https://support.apple.com/en-us/HT214122
Vendor Advisory
Release Notes
https://support.apple.com/en-us/HT214124
Vendor Advisory
Release Notes