CVE Vulnerabilities

CVE-2024-40848

Published: Sep 17, 2024 | Modified: Sep 24, 2024
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

A downgrade issue was addressed with additional code-signing restrictions. This issue is fixed in macOS Ventura 13.7, macOS Sonoma 14.7, macOS Sequoia 15. An attacker may be able to read sensitive information.

Affected Software

Name Vendor Start Version End Version
Macos Apple * 13.7 (excluding)
Macos Apple 14.0 (including) 14.7 (excluding)

References