CVE-2024-23282

The issue was addressed with improved checks. This issue is fixed in iOS 16.7.8 and iPadOS 16.7.8, iOS 17.5 and iPadOS 17.5, macOS Sonoma 14.5, watchOS 10.5. A maliciously crafted email may be able to initiate FaceTime calls without user authorization.
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:watchos:*:*:*:*:*:*:*:*

History

02 Apr 2026, 19:17

Type Values Removed Values Added
References
  • () https://support.apple.com/en-us/120898 -
  • () https://support.apple.com/en-us/120902 -
  • () https://support.apple.com/en-us/120903 -
  • () https://support.apple.com/en-us/120905 -
Summary (en) The issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14.5, watchOS 10.5, iOS 17.5 and iPadOS 17.5, iOS 16.7.8 and iPadOS 16.7.8. A maliciously crafted email may be able to initiate FaceTime calls without user authorization. (en) The issue was addressed with improved checks. This issue is fixed in iOS 16.7.8 and iPadOS 16.7.8, iOS 17.5 and iPadOS 17.5, macOS Sonoma 14.5, watchOS 10.5. A maliciously crafted email may be able to initiate FaceTime calls without user authorization.

21 Nov 2024, 08:57

Type Values Removed Values Added
References () https://support.apple.com/en-us/HT214100 - Vendor Advisory () https://support.apple.com/en-us/HT214100 - Vendor Advisory
References () https://support.apple.com/en-us/HT214101 - Vendor Advisory () https://support.apple.com/en-us/HT214101 - Vendor Advisory
References () https://support.apple.com/en-us/HT214104 - Vendor Advisory () https://support.apple.com/en-us/HT214104 - Vendor Advisory
References () https://support.apple.com/en-us/HT214106 - Vendor Advisory () https://support.apple.com/en-us/HT214106 - Vendor Advisory
References () https://support.apple.com/kb/HT214100 - Vendor Advisory () https://support.apple.com/kb/HT214100 - Vendor Advisory
References () https://support.apple.com/kb/HT214101 - Vendor Advisory () https://support.apple.com/kb/HT214101 - Vendor Advisory
References () https://support.apple.com/kb/HT214104 - Vendor Advisory () https://support.apple.com/kb/HT214104 - Vendor Advisory
References () https://support.apple.com/kb/HT214106 - Vendor Advisory () https://support.apple.com/kb/HT214106 - Vendor Advisory

30 Oct 2024, 20:35

Type Values Removed Values Added
CWE CWE-552

27 Jun 2024, 14:49

Type Values Removed Values Added
References () https://support.apple.com/en-us/HT214100 - () https://support.apple.com/en-us/HT214100 - Vendor Advisory
References () https://support.apple.com/en-us/HT214101 - () https://support.apple.com/en-us/HT214101 - Vendor Advisory
References () https://support.apple.com/en-us/HT214104 - () https://support.apple.com/en-us/HT214104 - Vendor Advisory
References () https://support.apple.com/en-us/HT214106 - () https://support.apple.com/en-us/HT214106 - Vendor Advisory
References () https://support.apple.com/kb/HT214100 - () https://support.apple.com/kb/HT214100 - Vendor Advisory
References () https://support.apple.com/kb/HT214101 - () https://support.apple.com/kb/HT214101 - Vendor Advisory
References () https://support.apple.com/kb/HT214104 - () https://support.apple.com/kb/HT214104 - Vendor Advisory
References () https://support.apple.com/kb/HT214106 - () https://support.apple.com/kb/HT214106 - Vendor Advisory
CWE NVD-CWE-noinfo
CPE cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:watchos:*:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.5
First Time Apple iphone Os
Apple macos
Apple
Apple watchos
Apple ipados

11 Jun 2024, 13:54

Type Values Removed Values Added
Summary
  • (es) El problema se solucionó con controles mejorados. Este problema se solucionó en macOS Sonoma 14.5, watchOS 10.5, iOS 17.5 y iPadOS 17.5, iOS 16.7.8 y iPadOS 16.7.8. Un correo electrónico creado con fines malintencionados puede iniciar llamadas FaceTime sin la autorización del usuario.

11 Jun 2024, 08:15

Type Values Removed Values Added
References
  • () https://support.apple.com/kb/HT214100 -
  • () https://support.apple.com/kb/HT214101 -
  • () https://support.apple.com/kb/HT214104 -
  • () https://support.apple.com/kb/HT214106 -

10 Jun 2024, 21:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-06-10 21:15

Updated : 2026-04-02 19:17


NVD link : CVE-2024-23282

Mitre link : CVE-2024-23282

CVE.ORG link : CVE-2024-23282


JSON object : View

Products Affected

apple

  • ipados
  • macos
  • iphone_os
  • watchos
CWE
NVD-CWE-noinfo CWE-552

Files or Directories Accessible to External Parties