CVE-2024-27835

This issue was addressed through improved state management. This issue is fixed in iOS 17.5 and iPadOS 17.5. An attacker with physical access to an iOS device may be able to access notes from the lock screen.
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*

History

12 Dec 2024, 14:33

Type Values Removed Values Added
CPE cpe:2.3:o:apple:ipad_os:*:*:*:*:*:*:*:* cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*
First Time Apple ipados

09 Dec 2024, 19:35

Type Values Removed Values Added
CWE NVD-CWE-noinfo
CPE cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:ipad_os:*:*:*:*:*:*:*:*
First Time Apple iphone Os
Apple
Apple ipad Os
References () http://seclists.org/fulldisclosure/2024/May/10 - () http://seclists.org/fulldisclosure/2024/May/10 - Mailing List
References () https://support.apple.com/en-us/HT214101 - () https://support.apple.com/en-us/HT214101 - Vendor Advisory
References () https://support.apple.com/kb/HT214101 - () https://support.apple.com/kb/HT214101 - Vendor Advisory

21 Nov 2024, 09:05

Type Values Removed Values Added
References () http://seclists.org/fulldisclosure/2024/May/10 - () http://seclists.org/fulldisclosure/2024/May/10 -
References () https://support.apple.com/en-us/HT214101 - () https://support.apple.com/en-us/HT214101 -
References () https://support.apple.com/kb/HT214101 - () https://support.apple.com/kb/HT214101 -

29 Aug 2024, 20:36

Type Values Removed Values Added
CWE CWE-287
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 2.4

10 Jun 2024, 18:15

Type Values Removed Values Added
References
  • () https://support.apple.com/kb/HT214101 -

10 Jun 2024, 17:16

Type Values Removed Values Added
Summary
  • (es) Esta cuestión se abordó mediante una mejora de gestión de estado. Este problema se solucionó en iOS 17.5 y iPadOS 17.5. Un atacante con acceso físico a un dispositivo iOS puede acceder a notas desde la pantalla de bloqueo.
References
  • () http://seclists.org/fulldisclosure/2024/May/10 -

14 May 2024, 15:13

Type Values Removed Values Added
New CVE

Information

Published : 2024-05-14 15:13

Updated : 2024-12-12 14:33


NVD link : CVE-2024-27835

Mitre link : CVE-2024-27835

CVE.ORG link : CVE-2024-27835


JSON object : View

Products Affected

apple

  • ipados
  • iphone_os
CWE
NVD-CWE-noinfo CWE-287

Improper Authentication