CVE-2024-23229

This issue was addressed with improved redaction of sensitive information. This issue is fixed in macOS Monterey 12.7.5, macOS Ventura 13.6.5, macOS Sonoma 14.4. A malicious application may be able to access Find My data.
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*

History

09 Dec 2024, 17:37

Type Values Removed Values Added
References () http://seclists.org/fulldisclosure/2024/May/14 - () http://seclists.org/fulldisclosure/2024/May/14 - Mailing List
References () https://support.apple.com/en-us/HT214084 - () https://support.apple.com/en-us/HT214084 - Vendor Advisory
References () https://support.apple.com/en-us/HT214085 - () https://support.apple.com/en-us/HT214085 - Vendor Advisory
References () https://support.apple.com/en-us/HT214105 - () https://support.apple.com/en-us/HT214105 - Vendor Advisory
References () https://support.apple.com/kb/HT214084 - () https://support.apple.com/kb/HT214084 - Vendor Advisory
References () https://support.apple.com/kb/HT214085 - () https://support.apple.com/kb/HT214085 - Vendor Advisory
References () https://support.apple.com/kb/HT214105 - () https://support.apple.com/kb/HT214105 - Vendor Advisory
First Time Apple
Apple macos
CPE cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
CWE NVD-CWE-noinfo

21 Nov 2024, 08:57

Type Values Removed Values Added
References () http://seclists.org/fulldisclosure/2024/May/14 - () http://seclists.org/fulldisclosure/2024/May/14 -
References () https://support.apple.com/en-us/HT214084 - () https://support.apple.com/en-us/HT214084 -
References () https://support.apple.com/en-us/HT214085 - () https://support.apple.com/en-us/HT214085 -
References () https://support.apple.com/en-us/HT214105 - () https://support.apple.com/en-us/HT214105 -
References () https://support.apple.com/kb/HT214084 - () https://support.apple.com/kb/HT214084 -
References () https://support.apple.com/kb/HT214085 - () https://support.apple.com/kb/HT214085 -
References () https://support.apple.com/kb/HT214105 - () https://support.apple.com/kb/HT214105 -

30 Oct 2024, 20:35

Type Values Removed Values Added
CWE CWE-922
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.5

10 Jun 2024, 19:15

Type Values Removed Values Added
References
  • () https://support.apple.com/kb/HT214105 -

10 Jun 2024, 17:16

Type Values Removed Values Added
References
  • () http://seclists.org/fulldisclosure/2024/May/14 -

10 Jun 2024, 16:15

Type Values Removed Values Added
References
  • () https://support.apple.com/kb/HT214084 -
  • () https://support.apple.com/kb/HT214085 -
Summary
  • (es) Este problema se solucionó mejorando la redacción de información confidencial. Este problema se solucionó en macOS Monterey 12.7.5, macOS Ventura 13.6.5, macOS Sonoma 14.4. Es posible que una aplicación maliciosa pueda acceder a Buscar mis datos.

14 May 2024, 14:58

Type Values Removed Values Added
New CVE

Information

Published : 2024-05-14 14:58

Updated : 2024-12-09 17:37


NVD link : CVE-2024-23229

Mitre link : CVE-2024-23229

CVE.ORG link : CVE-2024-23229


JSON object : View

Products Affected

apple

  • macos
CWE
NVD-CWE-noinfo CWE-922

Insecure Storage of Sensitive Information