← Volver a CVEs
CVE-2024-40840
MEDIUM4.6
Descripcion
This issue was addressed through improved state management. This issue is fixed in iOS 18 and iPadOS 18. An attacker with physical access may be able to use Siri to access sensitive user data.
Detalles CVE
Puntuacion CVSS v3.14.6
SeveridadMEDIUM
Vector CVSSCVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Vector de ataquePHYSICAL
ComplejidadLOW
Privilegios requeridosNONE
Interaccion usuarioNONE
Publicado9/17/2024
Ultima modificacion11/4/2025
Fuentenvd
Avistamientos honeypot0
Productos afectados
apple:ipadosapple:iphone_os
Referencias
https://support.apple.com/en-us/121250(product-security@apple.com)
http://seclists.org/fulldisclosure/2024/Sep/32(af854a3a-2127-422b-91ae-364da2661108)
Correlaciones IOC
Sin correlaciones registradas
This product uses data from the NVD API but is not endorsed or certified by the NVD.