CVE-2024-23204: Buffer Overflow
Accessibility. This issue was addressed with additional entitlement checks.
Other sources
Admin Framework. A logic issue was addressed with improved checks.
— Apple
Airport. This issue was addressed with improved redaction of sensitive information.
— Apple
Apple Neural Engine. The issue was addressed with improved memory handling.
— Apple
AppleMobileFileIntegrity. A downgrade issue affecting Intel-based Mac computers was addressed with additional code-signing restrictions.
— Apple
ColorSync. The issue was addressed with improved memory handling.
— Apple
Credit
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2024-23212
- CVE-2024-23218
- CVE-2024-23224
- CVE-2024-23208
- CVE-2024-23201
- CVE-2024-23209
- CVE-2024-23207
- CVE-2024-23223
- CVE-2024-27791
- CVE-2024-23211
- CVE-2024-23203
- CVE-2024-23204
- CVE-2024-23217
- CVE-2024-23215
- CVE-2024-23210
- CVE-2024-23206
- CVE-2024-23213
- CVE-2024-23214
- CVE-2024-23222
- CVE-2024-23271
- CVE-2024-23276
- CVE-2024-23227
- CVE-2024-23269
- CVE-2024-23247
- CVE-2024-23299
- CVE-2024-23244
- CVE-2024-23270
- CVE-2024-23286
- CVE-2024-23257
- CVE-2024-23234
- CVE-2024-23266
- CVE-2024-23265
- CVE-2024-23225
- CVE-2023-28826
- CVE-2024-23264
- CVE-2024-23283
- CVE-2024-23274
- CVE-2024-23268
- CVE-2024-23275
- CVE-2024-23267
- CVE-2024-23216
- CVE-2024-23230
- CVE-2024-23245
- CVE-2024-23272
- CVE-2023-40389
- CVE-2024-23229
- CVE-2024-23278
- CVE-2024-23231
- CVE-2024-23262
- CVE-2024-23235
- CVE-2024-23259
- CVE-2024-23289
- CVE-2024-23246
- CVE-2024-23284
- CVE-2024-23263
- CVE-2024-23228
- CVE-2024-23219
Frequently Asked Questions
What is the severity of CVE-2024-23204?
CVE-2024-23204 is considered a serious vulnerability due to the potential unauthorized use of sensitive data by shortcuts.
How do I fix CVE-2024-23204?
To fix CVE-2024-23204, update your device to macOS Sonoma 14.3, watchOS 10.3, iOS 17.3, or iPadOS 17.3.
Which Apple devices are affected by CVE-2024-23204?
CVE-2024-23204 affects devices running certain versions of iOS, iPadOS, watchOS, and macOS, specifically up to iOS and iPadOS 17.3 and watchOS 10.3.
What type of issue does CVE-2024-23204 address in Apple devices?
CVE-2024-23204 addresses an issue where shortcuts may access sensitive data without appropriate user prompts.
Is there a workaround for CVE-2024-23204?
There is no known workaround for CVE-2024-23204; users must update their devices to resolve the vulnerability.