A permissions issue was addressed to help ensure Personas are always protected This issue is fixed in visionOS 1.1. An unauthenticated user may be able to use an unprotected Persona.
References
Link | Resource |
---|---|
http://seclists.org/fulldisclosure/2024/Mar/26 | Mailing List |
https://support.apple.com/en-us/HT214087 | Vendor Advisory |
http://seclists.org/fulldisclosure/2024/Mar/26 | Mailing List |
https://support.apple.com/en-us/HT214087 | Vendor Advisory |
Configurations
History
09 Dec 2024, 16:09
Type | Values Removed | Values Added |
---|---|---|
First Time |
Apple
Apple visionos |
|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 5.5 |
References | () http://seclists.org/fulldisclosure/2024/Mar/26 - Mailing List | |
References | () https://support.apple.com/en-us/HT214087 - Vendor Advisory | |
CWE | CWE-276 | |
CPE | cpe:2.3:o:apple:visionos:*:*:*:*:*:*:*:* |
21 Nov 2024, 08:57
Type | Values Removed | Values Added |
---|---|---|
References | () http://seclists.org/fulldisclosure/2024/Mar/26 - | |
References | () https://support.apple.com/en-us/HT214087 - |
27 Oct 2024, 14:35
Type | Values Removed | Values Added |
---|---|---|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 6.2 |
13 Mar 2024, 23:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
08 Mar 2024, 02:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-03-08 02:15
Updated : 2024-12-09 16:09
NVD link : CVE-2024-23295
Mitre link : CVE-2024-23295
CVE.ORG link : CVE-2024-23295
JSON object : View
Products Affected
apple
- visionos
CWE
CWE-276
Incorrect Default Permissions