CVE-2024-40786

This issue was addressed through improved state management. This issue is fixed in iOS 17.6 and iPadOS 17.6, iOS 16.7.9 and iPadOS 16.7.9, macOS Ventura 13.6.8. An attacker may be able to view sensitive user information.
References
Link Resource
http://seclists.org/fulldisclosure/2024/Jul/16 Mailing List Third Party Advisory
http://seclists.org/fulldisclosure/2024/Jul/17 Mailing List Third Party Advisory
http://seclists.org/fulldisclosure/2024/Jul/19 Mailing List Third Party Advisory
https://support.apple.com/en-us/HT214116 Release Notes Vendor Advisory
https://support.apple.com/en-us/HT214117 Release Notes Vendor Advisory
https://support.apple.com/en-us/HT214120 Release Notes Vendor Advisory
http://seclists.org/fulldisclosure/2024/Jul/16 Mailing List Third Party Advisory
http://seclists.org/fulldisclosure/2024/Jul/17 Mailing List Third Party Advisory
http://seclists.org/fulldisclosure/2024/Jul/19 Mailing List Third Party Advisory
https://support.apple.com/en-us/HT214116 Release Notes Vendor Advisory
https://support.apple.com/en-us/HT214117 Release Notes Vendor Advisory
https://support.apple.com/en-us/HT214120 Release Notes Vendor Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*

Configuration 2 (hide)

OR cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*

Configuration 3 (hide)

cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*

History

19 Mar 2025, 20:15

Type Values Removed Values Added
CWE CWE-284

21 Nov 2024, 09:31

Type Values Removed Values Added
References () http://seclists.org/fulldisclosure/2024/Jul/16 - Mailing List, Third Party Advisory () http://seclists.org/fulldisclosure/2024/Jul/16 - Mailing List, Third Party Advisory
References () http://seclists.org/fulldisclosure/2024/Jul/17 - Mailing List, Third Party Advisory () http://seclists.org/fulldisclosure/2024/Jul/17 - Mailing List, Third Party Advisory
References () http://seclists.org/fulldisclosure/2024/Jul/19 - Mailing List, Third Party Advisory () http://seclists.org/fulldisclosure/2024/Jul/19 - Mailing List, Third Party Advisory
References () https://support.apple.com/en-us/HT214116 - Release Notes, Vendor Advisory () https://support.apple.com/en-us/HT214116 - Release Notes, Vendor Advisory
References () https://support.apple.com/en-us/HT214117 - Release Notes, Vendor Advisory () https://support.apple.com/en-us/HT214117 - Release Notes, Vendor Advisory
References () https://support.apple.com/en-us/HT214120 - Release Notes, Vendor Advisory () https://support.apple.com/en-us/HT214120 - Release Notes, Vendor Advisory

15 Aug 2024, 16:44

Type Values Removed Values Added
CWE NVD-CWE-noinfo
First Time Apple
Apple ipados
Apple iphone Os
Apple macos
CPE cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5
References () http://seclists.org/fulldisclosure/2024/Jul/16 - () http://seclists.org/fulldisclosure/2024/Jul/16 - Mailing List, Third Party Advisory
References () http://seclists.org/fulldisclosure/2024/Jul/17 - () http://seclists.org/fulldisclosure/2024/Jul/17 - Mailing List, Third Party Advisory
References () http://seclists.org/fulldisclosure/2024/Jul/19 - () http://seclists.org/fulldisclosure/2024/Jul/19 - Mailing List, Third Party Advisory
References () https://support.apple.com/en-us/HT214116 - () https://support.apple.com/en-us/HT214116 - Release Notes, Vendor Advisory
References () https://support.apple.com/en-us/HT214117 - () https://support.apple.com/en-us/HT214117 - Release Notes, Vendor Advisory
References () https://support.apple.com/en-us/HT214120 - () https://support.apple.com/en-us/HT214120 - Release Notes, Vendor Advisory

30 Jul 2024, 13:32

Type Values Removed Values Added
Summary
  • (es) Esta cuestión se abordó mediante una mejor gestión estatal. Este problema se solucionó en iOS 17.6 y iPadOS 17.6, iOS 16.7.9 y iPadOS 16.7.9, macOS Ventura 13.6.8. Un atacante puede ser capaz de ver información confidencial del usuario.

30 Jul 2024, 02:15

Type Values Removed Values Added
References
  • () http://seclists.org/fulldisclosure/2024/Jul/19 -

30 Jul 2024, 01:15

Type Values Removed Values Added
References
  • () http://seclists.org/fulldisclosure/2024/Jul/16 -
  • () http://seclists.org/fulldisclosure/2024/Jul/17 -

29 Jul 2024, 23:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-07-29 23:15

Updated : 2025-03-19 20:15


NVD link : CVE-2024-40786

Mitre link : CVE-2024-40786

CVE.ORG link : CVE-2024-40786


JSON object : View

Products Affected

apple

  • ipados
  • iphone_os
  • macos
CWE
NVD-CWE-noinfo CWE-284

Improper Access Control