CVE-2024-23207: Infoleak
Apple Neural Engine. The issue was addressed with improved memory handling.
Other sources
CoreCrypto. A timing side-channel issue was addressed with improvements to constant-time computation in cryptographic functions.
— Apple
Kernel. The issue was addressed with improved memory handling.
— Apple
libxpc. A permissions issue was addressed with additional restrictions.
— Apple
Mail Search. This issue was addressed with improved redaction of sensitive information.
— Apple
This issue was addressed with improved redaction of sensitive information. This issue is fixed in iOS 17.3 and iPadOS 17.3, macOS Monterey 12.7.3, macOS Sonoma 14.3, macOS Ventura 13.6.4, watchOS 10.3. An app may be able to access sensitive user data.
— MITRE
Credit
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Apple macOSto a version that resolves this vulnerability.Fixed in 14.3 - Upgrade
Upgrade
Apple iOS, iPadOS, and watchOSto a version that resolves this vulnerability.Fixed in 10.3 - Upgrade
Upgrade
macOSto a version that resolves this vulnerability.Fixed in 12.7.3 - Upgrade
Upgrade
macOS Venturato a version that resolves this vulnerability.Fixed in 13.6.4 - Upgrade
Upgrade
Apple iOS and iPadOSto a version that resolves this vulnerability.Fixed in 17.3 - Upgrade
Upgrade
Apple iOS, iPadOS, and macOSto a version that resolves this vulnerability.Fixed in 17.3 - Upgrade
Upgrade
Apple Neural Engineto a version that resolves this vulnerability.Fixed in 17.3 - Upgrade
Upgrade
CoreCryptoto a version that resolves this vulnerability.Fixed in 17.3 - Upgrade
Upgrade
Kernelto a version that resolves this vulnerability.Fixed in 17.3 - Upgrade
Upgrade
Mail Searchto a version that resolves this vulnerability.Fixed in 17.3 - Upgrade
Upgrade
libxpcto a version that resolves this vulnerability.Fixed in 17.3
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2024-23212
- CVE-2024-23218
- CVE-2024-23224
- CVE-2024-23208
- CVE-2024-23201
- CVE-2024-23209
- CVE-2024-23207
- CVE-2024-23223
- CVE-2024-27791
- CVE-2024-23211
- CVE-2024-23203
- CVE-2024-23204
- CVE-2024-23217
- CVE-2024-23215
- CVE-2024-23210
- CVE-2024-23206
- CVE-2024-23213
- CVE-2024-23214
- CVE-2024-23222
- CVE-2024-23271
- CVE-2023-42937
- CVE-2023-38545
- CVE-2023-38039
- CVE-2023-38546
- CVE-2023-42888
- CVE-2023-40528
- CVE-2023-42935
- CVE-2023-42887
- CVE-2024-23228
- CVE-2024-23219
Frequently Asked Questions
What is the severity of CVE-2024-23207?
CVE-2024-23207 has a medium severity rating, as it involves inadequate redaction of sensitive information.
How do I fix CVE-2024-23207?
To fix CVE-2024-23207, upgrade your device to watchOS 10.3, iOS 17.3, iPadOS 17.3, macOS Sonoma 14.3, macOS Ventura 13.6.4, or macOS Monterey 12.7.3.
Which devices are affected by CVE-2024-23207?
Devices affected by CVE-2024-23207 include those running older versions of watchOS, iOS, iPadOS, and macOS prior to the specified updated versions.
What information was inadequately redacted in CVE-2024-23207?
CVE-2024-23207 relates to the inadequacy in redacting sensitive information during mail search operations.
When was CVE-2024-23207 disclosed?
CVE-2024-23207 was disclosed alongside the patches released in early 2024.