CVE-2024-23220: Buffer Overflow
Accessibility. A privacy issue was addressed with improved private data redaction for log entries.
Other sources
Accessibility. This issue was addressed with additional entitlement checks.
— Apple
AppleMobileFileIntegrity. This issue was addressed by removing the vulnerable code.
— Apple
Bluetooth. The issue was addressed with improved checks.
— Apple
CoreBluetooth - LE. An access issue was addressed with improved access restrictions.
— Apple
ExtensionKit. A privacy issue was addressed with improved private data redaction for log entries.
— Apple
Credit
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2024-23262
- CVE-2024-23257
- CVE-2024-23258
- CVE-2024-23286
- CVE-2024-23235
- CVE-2024-23265
- CVE-2024-23225
- CVE-2024-23264
- CVE-2024-23295
- CVE-2024-23296
- CVE-2024-23220
- CVE-2024-23246
- CVE-2024-54658
- CVE-2024-23226
- CVE-2024-27859
- CVE-2024-23254
- CVE-2024-23263
- CVE-2024-23284
- CVE-2024-23243
- CVE-2024-23291
- CVE-2024-23288
- CVE-2024-23277
- CVE-2024-23250
- CVE-2024-23205
- CVE-2022-48554
- CVE-2024-23270
- CVE-2024-23278
- CVE-2024-0258
- CVE-2024-23297
- CVE-2024-23287
- CVE-2024-23240
- CVE-2024-23255
- CVE-2024-23259
- CVE-2024-23256
- CVE-2024-23273
- CVE-2024-23239
- CVE-2024-23290
- CVE-2024-23231
- CVE-2024-23292
- CVE-2024-23289
- CVE-2024-23293
- CVE-2024-23241
- CVE-2024-23242
- CVE-2024-23280
Frequently Asked Questions
What is the severity of CVE-2024-23220?
CVE-2024-23220 is classified as a high severity vulnerability affecting Safari that allows user fingerprinting.
How do I fix CVE-2024-23220?
To fix CVE-2024-23220, update to visionOS 1.1, iOS 17.4, or iPadOS 17.4.
What versions of software are affected by CVE-2024-23220?
CVE-2024-23220 affects versions of visionOS prior to 1.1 and iOS/iPadOS prior to 17.4.
What type of issue is described in CVE-2024-23220?
CVE-2024-23220 describes a vulnerability where apps may be able to fingerprint users due to cache handling.
Which products need to be updated for CVE-2024-23220?
The affected products that need to be updated for CVE-2024-23220 include Apple visionOS, iOS, and iPadOS.