CVE-2024-27803

A permissions issue was addressed with improved validation. This issue is fixed in iOS 17.5 and iPadOS 17.5. An attacker with physical access may be able to share items from the lock screen.
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*

History

25 Mar 2025, 19:15

Type Values Removed Values Added
CWE CWE-284

09 Dec 2024, 19:19

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 2.4
CPE cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*
References () http://seclists.org/fulldisclosure/2024/May/10 - () http://seclists.org/fulldisclosure/2024/May/10 - Mailing List
References () https://support.apple.com/en-us/HT214101 - () https://support.apple.com/en-us/HT214101 - Vendor Advisory
References () https://support.apple.com/kb/HT214101 - () https://support.apple.com/kb/HT214101 - Vendor Advisory
First Time Apple iphone Os
Apple
Apple ipados
CWE NVD-CWE-noinfo

21 Nov 2024, 09:05

Type Values Removed Values Added
References () http://seclists.org/fulldisclosure/2024/May/10 - () http://seclists.org/fulldisclosure/2024/May/10 -
References () https://support.apple.com/en-us/HT214101 - () https://support.apple.com/en-us/HT214101 -
References () https://support.apple.com/kb/HT214101 - () https://support.apple.com/kb/HT214101 -

10 Jun 2024, 18:15

Type Values Removed Values Added
References
  • () https://support.apple.com/kb/HT214101 -

10 Jun 2024, 17:16

Type Values Removed Values Added
Summary
  • (es) Se solucionó un problema de permisos con una validación mejorada. Este problema se solucionó en iOS 17.5 y iPadOS 17.5. Un atacante con acceso físico puede compartir elementos desde la pantalla de bloqueo.
References
  • () http://seclists.org/fulldisclosure/2024/May/10 -

14 May 2024, 15:13

Type Values Removed Values Added
New CVE

Information

Published : 2024-05-14 15:13

Updated : 2025-03-25 19:15


NVD link : CVE-2024-27803

Mitre link : CVE-2024-27803

CVE.ORG link : CVE-2024-27803


JSON object : View

Products Affected

apple

  • ipados
  • iphone_os
CWE
NVD-CWE-noinfo CWE-284

Improper Access Control