CVE-2024-40864

The issue was addressed with improved handling of protocols. This issue is fixed in iOS 18.2 and iPadOS 18.2, macOS Sequoia 15.2, macOS Sonoma 14.7.5, macOS Ventura 13.7.5, tvOS 18.2, watchOS 11.2. An attacker in a privileged network position may be able to track a user's activity.
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*

History

02 Apr 2026, 19:18

Type Values Removed Values Added
Summary (en) The issue was addressed with improved handling of protocols. This issue is fixed in macOS Ventura 13.7.5, macOS Sonoma 14.7.5. An attacker in a privileged network position can track a user's activity. (en) The issue was addressed with improved handling of protocols. This issue is fixed in iOS 18.2 and iPadOS 18.2, macOS Sequoia 15.2, macOS Sonoma 14.7.5, macOS Ventura 13.7.5, tvOS 18.2, watchOS 11.2. An attacker in a privileged network position may be able to track a user's activity.
References
  • () https://support.apple.com/en-us/121837 -
  • () https://support.apple.com/en-us/121839 -
  • () https://support.apple.com/en-us/121843 -
  • () https://support.apple.com/en-us/121844 -

03 Nov 2025, 21:16

Type Values Removed Values Added
References
  • () http://seclists.org/fulldisclosure/2025/Apr/10 -
  • () http://seclists.org/fulldisclosure/2025/Apr/9 -

04 Apr 2025, 18:19

Type Values Removed Values Added
Summary
  • (es) El problema se solucionó mejorando la gestión de protocolos. Este problema está corregido en macOS Ventura 13.7.5 y macOS Sonoma 14.7.5. Un atacante con una posición privilegiada en la red puede rastrear la actividad de un usuario.
First Time Apple macos
Apple
CPE cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
References () https://support.apple.com/en-us/122374 - () https://support.apple.com/en-us/122374 - Release Notes, Vendor Advisory
References () https://support.apple.com/en-us/122375 - () https://support.apple.com/en-us/122375 - Release Notes, Vendor Advisory

01 Apr 2025, 14:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : 9.8
v2 : unknown
v3 : 2.7

01 Apr 2025, 04:15

Type Values Removed Values Added
CWE CWE-200
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8

31 Mar 2025, 23:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-03-31 23:15

Updated : 2026-04-02 19:18


NVD link : CVE-2024-40864

Mitre link : CVE-2024-40864

CVE.ORG link : CVE-2024-40864


JSON object : View

Products Affected

apple

  • macos
CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor