Security features bypass in iPadOS and Apple iOS - CVE-2024-40813

 

Security features bypass in iPadOS and Apple iOS - CVE-2024-40813

Published: July 30, 2024


Vulnerability identifier: #VU94917
CSH Severity: Low
CVSS v4: 2.4 [CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-40813
CWE-ID: CWE-254
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows an attacker to bypass implemented security restrictions.

The vulnerability exists due to an error in Siri. An attacker with physical access to device can use Siri to access sensitive user data from the lock screen.


Affected software

iPadOS
Apple iOS
watchOS

How to mitigate CVE-2024-40813

Install updates from vendor's website.

iPadOS - update to 17.6 21G80
Apple iOS - update to 17.6 21G80
watchOS - update to 10.6

External References

Related Security Bulletins