CVE-2024-23203

The issue was addressed with additional permissions checks. This issue is fixed in iOS 16.7.6 and iPadOS 16.7.6, iOS 17.3 and iPadOS 17.3, macOS Sonoma 14.3, macOS Ventura 13.6.5. A shortcut may be able to use sensitive data with certain actions without prompting the user.
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*

History

02 Apr 2026, 19:16

Type Values Removed Values Added
Summary (en) The issue was addressed with additional permissions checks. This issue is fixed in macOS Sonoma 14.3, iOS 17.3 and iPadOS 17.3. A shortcut may be able to use sensitive data with certain actions without prompting the user. (en) The issue was addressed with additional permissions checks. This issue is fixed in iOS 16.7.6 and iPadOS 16.7.6, iOS 17.3 and iPadOS 17.3, macOS Sonoma 14.3, macOS Ventura 13.6.5. A shortcut may be able to use sensitive data with certain actions without prompting the user.
References
  • () https://support.apple.com/en-us/120304 -
  • () https://support.apple.com/en-us/120309 -
  • () https://support.apple.com/en-us/120880 -
  • () https://support.apple.com/en-us/120886 -

04 Nov 2025, 19:16

Type Values Removed Values Added
References
  • () https://support.apple.com/kb/HT214061 -

21 Nov 2024, 08:57

Type Values Removed Values Added
References () http://seclists.org/fulldisclosure/2024/Jan/33 - Third Party Advisory () http://seclists.org/fulldisclosure/2024/Jan/33 - Third Party Advisory
References () http://seclists.org/fulldisclosure/2024/Jan/36 - Third Party Advisory () http://seclists.org/fulldisclosure/2024/Jan/36 - Third Party Advisory
References () http://seclists.org/fulldisclosure/2024/Mar/22 - () http://seclists.org/fulldisclosure/2024/Mar/22 -
References () https://support.apple.com/en-us/HT214059 - Release Notes, Vendor Advisory () https://support.apple.com/en-us/HT214059 - Release Notes, Vendor Advisory
References () https://support.apple.com/en-us/HT214061 - Release Notes, Vendor Advisory () https://support.apple.com/en-us/HT214061 - Release Notes, Vendor Advisory
References () https://support.apple.com/kb/HT214082 - () https://support.apple.com/kb/HT214082 -
References () https://support.apple.com/kb/HT214085 - () https://support.apple.com/kb/HT214085 -

13 Mar 2024, 22:15

Type Values Removed Values Added
References
  • () http://seclists.org/fulldisclosure/2024/Mar/22 -

08 Mar 2024, 19:15

Type Values Removed Values Added
References
  • () https://support.apple.com/kb/HT214085 -

07 Mar 2024, 19:15

Type Values Removed Values Added
References
  • () https://support.apple.com/kb/HT214082 -

26 Jan 2024, 21:14

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5
CWE NVD-CWE-noinfo
First Time Apple iphone Os
Apple macos
Apple
Apple ipados
References () https://support.apple.com/en-us/HT214059 - () https://support.apple.com/en-us/HT214059 - Release Notes, Vendor Advisory
References () http://seclists.org/fulldisclosure/2024/Jan/36 - () http://seclists.org/fulldisclosure/2024/Jan/36 - Third Party Advisory
References () http://seclists.org/fulldisclosure/2024/Jan/33 - () http://seclists.org/fulldisclosure/2024/Jan/33 - Third Party Advisory
References () https://support.apple.com/en-us/HT214061 - () https://support.apple.com/en-us/HT214061 - Release Notes, Vendor Advisory
CPE cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*

26 Jan 2024, 17:15

Type Values Removed Values Added
References
  • () http://seclists.org/fulldisclosure/2024/Jan/36 -
  • () http://seclists.org/fulldisclosure/2024/Jan/33 -

23 Jan 2024, 01:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-01-23 01:15

Updated : 2026-04-02 19:16


NVD link : CVE-2024-23203

Mitre link : CVE-2024-23203

CVE.ORG link : CVE-2024-23203


JSON object : View

Products Affected

apple

  • ipados
  • macos
  • iphone_os