6.6

CVE-2025-24198

This issue was addressed by restricting options offered on a locked device. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. An attacker with physical access may be able to use Siri to access sensitive user data.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Apple ≫ iPadOS Version < 17.7.6
Apple ≫ iPadOS Version >= 18.0 < 18.4
Apple ≫ iPhone OS Version < 18.4
Apple ≫ macOS Version >= 13.0 < 13.7.5
Apple ≫ macOS Version >= 14.0 < 14.7.5
Apple ≫ macOS Version >= 15.0 < 15.4
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.42% 0.349
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
CISA-ADP 6.6 0.7 5.9
CVSS:3.1/AV:P/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CWE-284 Improper Access Control

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

https://support.apple.com/en-us/122374
Vendor Advisory
https://support.apple.com/en-us/122375
Vendor Advisory
https://support.apple.com/en-us/122371
Vendor Advisory
https://support.apple.com/en-us/122373
Vendor Advisory
https://support.apple.com/en-us/122372
Vendor Advisory
http://seclists.org/fulldisclosure/2025/Apr/8
http://seclists.org/fulldisclosure/2025/Apr/4
http://seclists.org/fulldisclosure/2025/Apr/10
http://seclists.org/fulldisclosure/2025/Apr/5
http://seclists.org/fulldisclosure/2025/Apr/9