CVE-2024-40822
Apple
CVE-2024-40822 allows unauthorized access to contacts from a locked Apple device. This vulnerability, patched in watchOS 10.6, macOS Sonoma 14.6, and iOS/iPadOS 17.6 and 16.7.9, permits an attacker with physical access to bypass security measures. While the CVSS score is low (2.4), indicating minimal impact, the SOCRadar Vulnerability Risk Score (SVRS) of 32 suggests a slightly elevated risk due to potential exploitability in specific contexts. This security flaw could enable a malicious actor to gather sensitive information from the victim's contact list. Although the SVRS isn't critical (above 80), immediate patching is recommended to mitigate the risk of unauthorized contact access. The fix involves restricting options available on locked devices, enhancing overall device security. Ignoring this patch could lead to privacy breaches if devices are left unattended.
Indicators of Compromise
Exploits
News
Social Media
Affected Software
References
CWE Details
CVE Radar
Real-time CVE Intelligence & Vulnerability Management Platform
CVE Radar provides comprehensive vulnerability intelligence by monitoring CVE databases, security advisories, and threat feeds. Get instant updates on new vulnerabilities, exploit details, and mitigation strategies specific to your assets.