CVE-2024-23211: Low severity Apple macOS Sonoma vulnerability
A privacy issue was addressed with improved handling of user preferences. This issue is fixed in Safari 17.3, iOS 16.7.5 and iPadOS 16.7.5, iOS 17.3 and iPadOS 17.3, macOS Sonoma 14.3, watchOS 10.3. A user's private browsing activity may be visible in Settings.
Other sources
Apple Neural Engine. The issue was addressed with improved memory handling.
— Apple
CoreCrypto. A timing side-channel issue was addressed with improvements to constant-time computation in cryptographic functions.
— Apple
Kernel. The issue was addressed with improved memory handling.
— Apple
libxpc. A permissions issue was addressed with additional restrictions.
— Apple
Mail Search. This issue was addressed with improved redaction of sensitive information.
— Apple
Credit
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2024-23212
- CVE-2024-23218
- CVE-2024-23224
- CVE-2024-23208
- CVE-2024-23201
- CVE-2024-23209
- CVE-2024-23207
- CVE-2024-23223
- CVE-2024-27791
- CVE-2024-23211
- CVE-2024-23203
- CVE-2024-23204
- CVE-2024-23217
- CVE-2024-23215
- CVE-2024-23210
- CVE-2024-23206
- CVE-2024-23213
- CVE-2024-23214
- CVE-2024-23222
- CVE-2024-23271
- CVE-2024-23228
- CVE-2024-23219
- CVE-2023-42937
- CVE-2023-42888
Frequently Asked Questions
What is the severity of CVE-2024-23211?
CVE-2024-23211 is classified as a privacy issue due to the handling of user preferences.
How do I fix CVE-2024-23211?
To fix CVE-2024-23211, update to the latest versions of the affected products which include watchOS 10.3, iOS 17.3, iPadOS 17.3, macOS Sonoma 14.3, and Safari 17.3.
Which software versions are affected by CVE-2024-23211?
CVE-2024-23211 affects watchOS versions prior to 10.3, iOS versions before 17.3 and 16.7.5, iPadOS versions before 17.3 and 16.7.5, and macOS prior to 14.3.
What kind of issue is CVE-2024-23211 classified as?
CVE-2024-23211 is classified as a privacy issue related to visible private browsing activity.
When was CVE-2024-23211 reported?
CVE-2024-23211 was reported and acknowledged with improvements in handling user preferences released in the associated updates.