CVE-2024-23210: Low severity Apple macOS Sonoma vulnerability
Apple Neural Engine. The issue was addressed with improved memory handling.
Other sources
CoreCrypto. A timing side-channel issue was addressed with improvements to constant-time computation in cryptographic functions.
— Apple
Kernel. The issue was addressed with improved memory handling.
— Apple
libxpc. A permissions issue was addressed with additional restrictions.
— Apple
Mail Search. This issue was addressed with improved redaction of sensitive information.
— Apple
NSSpellChecker. A privacy issue was addressed with improved handling of files.
— Apple
Credit
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2024-23212
- CVE-2024-23218
- CVE-2024-23224
- CVE-2024-23208
- CVE-2024-23201
- CVE-2024-23209
- CVE-2024-23207
- CVE-2024-23223
- CVE-2024-27791
- CVE-2024-23211
- CVE-2024-23203
- CVE-2024-23204
- CVE-2024-23217
- CVE-2024-23215
- CVE-2024-23210
- CVE-2024-23206
- CVE-2024-23213
- CVE-2024-23214
- CVE-2024-23222
- CVE-2024-23271
- CVE-2024-23228
- CVE-2024-23219
Frequently Asked Questions
What is the severity of CVE-2024-23210?
The severity of CVE-2024-23210 is classified as moderate due to the risk of unauthorized access to sensitive user information.
How do I fix CVE-2024-23210?
To fix CVE-2024-23210, update to macOS Sonoma 14.3, watchOS 10.3, tvOS 17.3, iOS 17.3, or iPadOS 17.3.
What products are affected by CVE-2024-23210?
CVE-2024-23210 affects macOS, iOS, iPadOS, watchOS, and tvOS versions prior to the specified updates.
What information is at risk with CVE-2024-23210?
CVE-2024-23210 potentially exposes a user's phone number in system logs.
When was CVE-2024-23210 addressed?
CVE-2024-23210 was addressed in updates released for macOS and Apple’s other platforms in early 2024.