CVE Vulnerabilities

CVE-2024-23203

Published: Jan 23, 2024 | Modified: Apr 02, 2026
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

The issue was addressed with additional permissions checks. This issue is fixed in iOS 16.7.6 and iPadOS 16.7.6, iOS 17.3 and iPadOS 17.3, macOS Sonoma 14.3, macOS Ventura 13.6.5. A shortcut may be able to use sensitive data with certain actions without prompting the user.

Affected Software

NameVendorStart VersionEnd Version
IpadosApple17.0 (excluding)17.3 (excluding)
Iphone_osApple17.0 (excluding)17.3 (excluding)
MacosApple*14.3 (excluding)

References