CVE Radar Logo
CVERadar
CVE Radar Logo
CVERadar

CVE-2024-40834

Medium Severity
Apple
SVRS
30/100

CVSSv3
4.4/10

EPSS
0.00032/1

CVE-2024-40834 is a security vulnerability in macOS that allows a shortcut to potentially bypass sensitive Shortcuts app settings. Apple addressed this issue by adding an additional prompt for user consent in macOS Sonoma 14.6, macOS Monterey 12.7.6, and macOS Ventura 13.6.8. While the CVSS score is 4.4, indicating a medium severity, the SOCRadar Vulnerability Risk Score (SVRS) is 30. Although the SVRS score of 30 suggests it's not a critical vulnerability requiring immediate action, organizations using macOS should still apply the updates to mitigate the risk of unauthorized access to sensitive settings via malicious shortcuts. Ignoring this vulnerability could lead to privacy breaches or unauthorized modifications of system configurations through exploited shortcuts. Timely patching is advised to maintain a secure macOS environment. This highlights the importance of promptly updating macOS to protect against potential exploitation.

No tags available
CVSS:3.1
AV:L
AC:L
PR:L
UI:N
S:U
C:L
I:L
A:N
2024-07-29

2025-03-14

Indicators of Compromise

No IOCs found for this CVE

Exploits

No exploits found for this CVE

Enhance Your CVE Management with SOCRadar Vulnerability Intelligence
Get comprehensive CVE details, real-time notifications, and proactive threat management all in one platform.
CVE Details
Access comprehensive CVE information instantly
Real-time Tracking
Subscribe to CVEs and get instant updates
Exploit Analysis
Monitor related APT groups and threats
IOC Tracking
Analyze and track CVE-related IOCs

News

CVE-2024-40834 | Apple macOS up to 12.7.5/13.6.7/14.5 Shortcut Remote Code Execution
vuldb.com2025-03-16
CVE-2024-40834 | Apple macOS up to 12.7.5/13.6.7/14.5 Shortcut Remote Code Execution | A vulnerability, which was classified as critical, was found in Apple macOS up to 12.7.5/13.6.7/14.5. This affects an unknown part of the component Shortcut Handler. The manipulation leads to Remote Code Execution. This vulnerability is uniquely identified as CVE-2024-40834. It is possible to initiate the attack remotely. There
vuldb.com
rss
forum
news

Social Media

CVE-2024-40834 This issue was addressed by adding an additional prompt for user consent. This issue is fixed in macOS Sonoma 14.6, macOS Monterey 12.7.6, macOS Ventura 13.6.8. A sho… https://t.co/ZQ20kfqJeZ
0
0
0

Affected Software

Configuration 1
TypeVendorProduct
OSApplemacos

References

ReferenceLink
[email protected]https://support.apple.com/en-us/HT214118
[email protected]https://support.apple.com/en-us/HT214119
[email protected]https://support.apple.com/en-us/HT214120
[email protected]http://seclists.org/fulldisclosure/2024/Jul/18
[email protected]http://seclists.org/fulldisclosure/2024/Jul/19
[email protected]http://seclists.org/fulldisclosure/2024/Jul/20
[email protected]https://support.apple.com/en-us/HT214118
[email protected]https://support.apple.com/en-us/HT214119
[email protected]https://support.apple.com/en-us/HT214120
AF854A3A-2127-422B-91AE-364DA2661108http://seclists.org/fulldisclosure/2024/Jul/18
AF854A3A-2127-422B-91AE-364DA2661108http://seclists.org/fulldisclosure/2024/Jul/19
AF854A3A-2127-422B-91AE-364DA2661108http://seclists.org/fulldisclosure/2024/Jul/20
AF854A3A-2127-422B-91AE-364DA2661108https://support.apple.com/en-us/HT214118
AF854A3A-2127-422B-91AE-364DA2661108https://support.apple.com/en-us/HT214119
AF854A3A-2127-422B-91AE-364DA2661108https://support.apple.com/en-us/HT214120
[email protected]http://seclists.org/fulldisclosure/2024/Jul/18
[email protected]http://seclists.org/fulldisclosure/2024/Jul/19
[email protected]http://seclists.org/fulldisclosure/2024/Jul/20
[email protected]https://support.apple.com/en-us/HT214118
[email protected]https://support.apple.com/en-us/HT214119
[email protected]https://support.apple.com/en-us/HT214120
GITHUBhttp://seclists.org/fulldisclosure/2024/Jul/18
GITHUBhttp://seclists.org/fulldisclosure/2024/Jul/19

CWE Details

CWE IDCWE NameDescription
CWE-862Missing AuthorizationThe software does not perform an authorization check when an actor attempts to access a resource or perform an action.

CVE Radar

Real-time CVE Intelligence & Vulnerability Management Platform

CVE Radar provides comprehensive vulnerability intelligence by monitoring CVE databases, security advisories, and threat feeds. Get instant updates on new vulnerabilities, exploit details, and mitigation strategies specific to your assets.

Get Free Vulnerability Intelligence AccessAccess real-time CVE monitoring, exploit analysis, and threat intelligence