CVE Radar Logo
CVERadar
CVE Radar Logo
CVERadar

CVE-2024-40822

Medium Severity
Apple
SVRS
32/100

CVSSv3
2.4/10

EPSS
0.00112/1

CVE-2024-40822 allows unauthorized access to contacts from a locked Apple device. This vulnerability, patched in watchOS 10.6, macOS Sonoma 14.6, and iOS/iPadOS 17.6 and 16.7.9, permits an attacker with physical access to bypass security measures. While the CVSS score is low (2.4), indicating minimal impact, the SOCRadar Vulnerability Risk Score (SVRS) of 32 suggests a slightly elevated risk due to potential exploitability in specific contexts. This security flaw could enable a malicious actor to gather sensitive information from the victim's contact list. Although the SVRS isn't critical (above 80), immediate patching is recommended to mitigate the risk of unauthorized contact access. The fix involves restricting options available on locked devices, enhancing overall device security. Ignoring this patch could lead to privacy breaches if devices are left unattended.

No tags available
CVSS:3.1
AV:P
AC:L
PR:N
UI:N
S:U
C:L
I:N
A:N
2024-07-29

2025-03-27

Indicators of Compromise

No IOCs found for this CVE

Exploits

No exploits found for this CVE

Enhance Your CVE Management with SOCRadar Vulnerability Intelligence
Get comprehensive CVE details, real-time notifications, and proactive threat management all in one platform.
CVE Details
Access comprehensive CVE information instantly
Real-time Tracking
Subscribe to CVEs and get instant updates
Exploit Analysis
Monitor related APT groups and threats
IOC Tracking
Analyze and track CVE-related IOCs

News

No news found for this CVE

Social Media

CVE-2024-40822 This issue was addressed by restricting options offered on a locked device. This issue is fixed in watchOS 10.6, macOS Sonoma 14.6, iOS 17.6 and iPadOS 17.6, iOS 16.7… https://t.co/8fBXCNZfaT
0
0
0

Affected Software

Configuration 1
TypeVendorProduct
OSAppleiphone_os
OSApplemacos
OSApplewatchos
OSAppleipados

References

ReferenceLink
[email protected]https://support.apple.com/en-us/HT214116
[email protected]https://support.apple.com/en-us/HT214117
[email protected]https://support.apple.com/en-us/HT214119
[email protected]https://support.apple.com/en-us/HT214124
[email protected]http://seclists.org/fulldisclosure/2024/Jul/16
[email protected]http://seclists.org/fulldisclosure/2024/Jul/17
[email protected]http://seclists.org/fulldisclosure/2024/Jul/18
[email protected]http://seclists.org/fulldisclosure/2024/Jul/21
[email protected]https://support.apple.com/en-us/HT214116
[email protected]https://support.apple.com/en-us/HT214117
[email protected]https://support.apple.com/en-us/HT214119
[email protected]https://support.apple.com/en-us/HT214124
GITHUBhttp://seclists.org/fulldisclosure/2024/Jul/16
AF854A3A-2127-422B-91AE-364DA2661108http://seclists.org/fulldisclosure/2024/Jul/16
AF854A3A-2127-422B-91AE-364DA2661108http://seclists.org/fulldisclosure/2024/Jul/17
AF854A3A-2127-422B-91AE-364DA2661108http://seclists.org/fulldisclosure/2024/Jul/18
AF854A3A-2127-422B-91AE-364DA2661108http://seclists.org/fulldisclosure/2024/Jul/21
AF854A3A-2127-422B-91AE-364DA2661108https://support.apple.com/en-us/HT214116
AF854A3A-2127-422B-91AE-364DA2661108https://support.apple.com/en-us/HT214117
AF854A3A-2127-422B-91AE-364DA2661108https://support.apple.com/en-us/HT214119
AF854A3A-2127-422B-91AE-364DA2661108https://support.apple.com/en-us/HT214124
[email protected]http://seclists.org/fulldisclosure/2024/Jul/16
[email protected]http://seclists.org/fulldisclosure/2024/Jul/17
[email protected]http://seclists.org/fulldisclosure/2024/Jul/18
[email protected]http://seclists.org/fulldisclosure/2024/Jul/21
[email protected]https://support.apple.com/en-us/HT214116
[email protected]https://support.apple.com/en-us/HT214117
[email protected]https://support.apple.com/en-us/HT214119
[email protected]https://support.apple.com/en-us/HT214124

CWE Details

CWE IDCWE NameDescription
CWE-284Improper Access ControlThe software does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

CVE Radar

Real-time CVE Intelligence & Vulnerability Management Platform

CVE Radar provides comprehensive vulnerability intelligence by monitoring CVE databases, security advisories, and threat feeds. Get instant updates on new vulnerabilities, exploit details, and mitigation strategies specific to your assets.

Get Free Vulnerability Intelligence AccessAccess real-time CVE monitoring, exploit analysis, and threat intelligence