Protection Mechanism Failure in macOS - CVE-2024-44179
Published: March 5, 2025
Vulnerability identifier: #VU105366
CSH Severity: Low
CVSS v4.0: CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2024-44179
CWE-ID: CWE-693
Exploitation vector: Local access
Exploit availability:
No public exploit available
Affected software:
macOS
iPadOS
Apple iOS
macOS
iPadOS
Apple iOS
Detailed vulnerability description
The vulnerability allows an attacker to bypass implemented security restrictions.
The vulnerability exists due to presence of insecure features in Siri on a locked device. An attacker with physical access to device can read contact numbers from the lock screen.
How to mitigate CVE-2024-44179
Install updates from vendor's website.