CVE-2024-23224: Infoleak
Finder. The issue was addressed with improved checks.
Other sources
The issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14.3, macOS Ventura 13.6.4. An app may be able to access sensitive user data.
— MITRE
Credit
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Apple macOSto a version that resolves this vulnerability.Fixed in 14.3 - Upgrade
Upgrade
macOS Venturato a version that resolves this vulnerability.Fixed in 13.6.4 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 14.3 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 13.6.4
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2024-23212
- CVE-2024-23218
- CVE-2024-23224
- CVE-2024-23208
- CVE-2024-23201
- CVE-2024-23209
- CVE-2024-23207
- CVE-2024-23223
- CVE-2024-27791
- CVE-2024-23211
- CVE-2024-23203
- CVE-2024-23204
- CVE-2024-23217
- CVE-2024-23215
- CVE-2024-23210
- CVE-2024-23206
- CVE-2024-23213
- CVE-2024-23214
- CVE-2024-23222
- CVE-2024-23271
- CVE-2023-42937
- CVE-2023-40528
- CVE-2023-38545
- CVE-2023-38039
- CVE-2023-38546
- CVE-2023-42888
- CVE-2023-42935
- CVE-2023-42887
Frequently Asked Questions
What is the severity of CVE-2024-23224?
CVE-2024-23224 is classified as a medium severity vulnerability that may allow an app to access sensitive user data.
How do I fix CVE-2024-23224?
To fix CVE-2024-23224, update your system to macOS Sonoma version 14.3 or macOS Ventura version 13.6.4.
What software is affected by CVE-2024-23224?
CVE-2024-23224 affects macOS versions 13.0 to 13.6.4 and versions 14.0 to 14.2.
What type of vulnerability is CVE-2024-23224?
CVE-2024-23224 is a vulnerability related to improper access controls that can lead to unauthorized access to user data.
Is there a patch for CVE-2024-23224?
Yes, a patch for CVE-2024-23224 is included in macOS updates 14.3 and 13.6.4.