TROYANOSYVIRUS
Volver a CVEs

CVE-2024-40840

MEDIUM
4.6

Descripcion

This issue was addressed through improved state management. This issue is fixed in iOS 18 and iPadOS 18. An attacker with physical access may be able to use Siri to access sensitive user data.

Detalles CVE

Puntuacion CVSS v3.14.6
SeveridadMEDIUM
Vector CVSSCVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Vector de ataquePHYSICAL
ComplejidadLOW
Privilegios requeridosNONE
Interaccion usuarioNONE
Publicado9/17/2024
Ultima modificacion11/4/2025
Fuentenvd
Avistamientos honeypot0

Productos afectados

apple:ipadosapple:iphone_os

Referencias

https://support.apple.com/en-us/121250(product-security@apple.com)
http://seclists.org/fulldisclosure/2024/Sep/32(af854a3a-2127-422b-91ae-364da2661108)

Correlaciones IOC

Sin correlaciones registradas

This product uses data from the NVD API but is not endorsed or certified by the NVD.