CVE-2024-23217: Buffer Overflow
A privacy issue was addressed with improved handling of temporary files. This issue is fixed in iOS 17.3 and iPadOS 17.3, macOS Sonoma 14.3, macOS Ventura 13.6.5, watchOS 10.3. An app may be able to bypass certain Privacy preferences.
Other sources
Admin Framework. A logic issue was addressed with improved checks.
— Apple
Airport. This issue was addressed with improved redaction of sensitive information.
— Apple
Apple Neural Engine. The issue was addressed with improved memory handling.
— Apple
AppleMobileFileIntegrity. A downgrade issue affecting Intel-based Mac computers was addressed with additional code-signing restrictions.
— Apple
ColorSync. The issue was addressed with improved memory handling.
— Apple
Credit
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Apple macOSto a version that resolves this vulnerability.Fixed in 14.3 - Upgrade
Upgrade
Apple iOS, iPadOS, and watchOSto a version that resolves this vulnerability.Fixed in 10.3 - Upgrade
Upgrade
macOS Venturato a version that resolves this vulnerability.Fixed in 13.6.5 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 13.6.5 - Upgrade
Upgrade
Apple iOS and iPadOSto a version that resolves this vulnerability.Fixed in 17.3 - Upgrade
Upgrade
Apple iOS, iPadOS, and macOSto a version that resolves this vulnerability.Fixed in 17.3 - Upgrade
Upgrade
iOSto a version that resolves this vulnerability.Fixed in 17.3 - Upgrade
Upgrade
iPadOSto a version that resolves this vulnerability.Fixed in 17.3 - Upgrade
Upgrade
macOS Sonomato a version that resolves this vulnerability.Fixed in 14.3 - Upgrade
Upgrade
watchOSto a version that resolves this vulnerability.Fixed in 10.3
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2024-23212
- CVE-2024-23218
- CVE-2024-23224
- CVE-2024-23208
- CVE-2024-23201
- CVE-2024-23209
- CVE-2024-23207
- CVE-2024-23223
- CVE-2024-27791
- CVE-2024-23211
- CVE-2024-23203
- CVE-2024-23204
- CVE-2024-23217
- CVE-2024-23215
- CVE-2024-23210
- CVE-2024-23206
- CVE-2024-23213
- CVE-2024-23214
- CVE-2024-23222
- CVE-2024-23271
- CVE-2024-23276
- CVE-2024-23227
- CVE-2024-23269
- CVE-2024-23247
- CVE-2024-23299
- CVE-2024-23229
- CVE-2024-23270
- CVE-2024-23286
- CVE-2024-23257
- CVE-2024-23234
- CVE-2024-23266
- CVE-2024-23265
- CVE-2024-23225
- CVE-2024-23278
- CVE-2023-28826
- CVE-2024-23264
- CVE-2024-23283
- CVE-2024-23274
- CVE-2024-23268
- CVE-2024-23275
- CVE-2024-23267
- CVE-2024-23216
- CVE-2024-23231
- CVE-2024-23230
- CVE-2024-23245
- CVE-2024-23272
- CVE-2023-40389
- CVE-2024-23228
- CVE-2024-23219
Frequently Asked Questions
What is the severity of CVE-2024-23217?
CVE-2024-23217 is considered a privacy issue related to temporary file handling.
How do I fix CVE-2024-23217?
To fix CVE-2024-23217, upgrade to macOS Sonoma 14.3, watchOS 10.3, iOS 17.3, or iPadOS 17.3.
Which devices are affected by CVE-2024-23217?
CVE-2024-23217 affects various Apple devices running macOS, iOS, iPadOS, and watchOS prior to the specified versions.
What type of issue is CVE-2024-23217 related to?
CVE-2024-23217 is related to a privacy issue that may allow apps to bypass certain privacy preferences.
What did Apple do to address CVE-2024-23217?
Apple addressed CVE-2024-23217 with improved handling of temporary files in the latest software updates.