Security features bypass in iPadOS and Apple iOS - CVE-2024-40813
Published: July 30, 2024
Vulnerability identifier: #VU94917
CSH Severity: Low
CVSS v4: 2.4 [CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-40813
CWE-ID: CWE-254
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows an attacker to bypass implemented security restrictions.
The vulnerability exists due to an error in Siri. An attacker with physical access to device can use Siri to access sensitive user data from the lock screen.
Affected software
iPadOS
Apple iOS
watchOS
Apple iOS
watchOS
How to mitigate CVE-2024-40813
Install updates from vendor's website.
iPadOS - update to 17.6 21G80
Apple iOS - update to 17.6 21G80
watchOS - update to 10.6
Apple iOS - update to 17.6 21G80
watchOS - update to 10.6