CVE-2024-23229: Input Validation
Published Mar 7, 2024
·Updated
Accessibility. A privacy issue was addressed with improved private data redaction for log entries.
Credit
Joshua Jewett@@JoshJewett33, an anonymous researcher, Kirin@@Pwnrin, 小来来@@Smi1eSEC, pattern-f@@pattern_F_(Ant Security Light), Amir Bazine(CrowdStrike Counter Adversary Operations), Karsten König(CrowdStrike Counter Adversary Operations), Yann GASCUEL(Alter Solutions), Mickey Jin@@patch1t, Pr(Bar), Pr(Hebrew University), EP, LFY@@secsys(Fudan University), Daniel Zajork, Joshua Zajork, Meysam Firouzi@@R00tkitsmm(Trend Micro Zero Day Initiative), Pedro Tôrres@@t0rr3sp3dr0, CVE-2024-27806, ajajfxhj, m4yfly with TianGong Team(Legendsec at Qi'anxin Group), Guilherme Rambo(Best Buddy Apps), Csaba Fitzl@@theevilbit(OffSec), CVE-2024-23205, CVE-2022-48554, Junsung Lee(Trend Micro Zero Day Initiative), Zhenjiang Zhao(pangu team), Qianxin(CrowdStrike Counter Adversary Operations), (CrowdStrike Counter Adversary Operations), Dohyun Lee@@l33d0hyun, Lyutoon, Mr.R, Murray Mike, CVE-2024-23235, Xinru Chi(Pangu Lab), CVE-2024-23225, koocola, ali yabuz, @@08Tc3wBB(Jamf), CVE-2024-23283, CVE-2023-48795, CVE-2023-51384, CVE-2023-51385, Bohdan Stasiuk@@Bohdan_Stasiuk, Harsh Tyagi, Wojciech Regula(SecuRing), CVE-2024-23296, Lyra Rebane (rebane2001), Matej Rabzelj, CVE-2024-23238, Yiğit Can YILMAZ@@yilmazcanyigit, luckyu@@uuulucky, K宝(Fudan University), Lewis Hardy, Bistrit Dahal, CVE-2024-23241, CVE-2024-23242, Matthew Loewen, Deutsche Telekom Security GmbH sponsored by Bundesamt für Sicherheit in der Informationstechnik, anbu1024(SecANT), Pwn2car, James Lee@@Windowsrcer, Johan Carlsson (joaxcar), Georg Felber, Marco Squarcina, Marc Newlin(SkySafe), Brian McNulty, Stephan Casas, CVE-2024-23291, Clemens Lang, Koh M. Nakagawa(FFRI Security Inc), Meng Zhang (鲸落)(NorthSea), Jubaer Alnazi@@h33tjubaer, Csaba Fitzl@@theevilbit(Offensive Security)
Affected Software
6 affected componentsFixes available
Apple macOS<14.4
14.4
macOS<12.7.5
12.7.5
macOS Ventura<13.6.5
13.6.5
macOS>=12.0<12.7.5
macOS>=13.0<13.6.5
macOS>=14.0<14.4
Event History
Mar 7, 2024
Data Sourced
via Apple·12:00 AM
DescriptionWeaknessAffected Software
Updated
via Apple·12:00 AM
DescriptionWeakness
May 13, 2024
Updated
via Apple·12:00 AM
DescriptionWeaknessAffected Software
CVE Published
via MITRE·11:00 PM
Data Sourced
via MITRE·11:00 PM
DescriptionWeakness
May 14, 2024
Data Sourced
via NVD·02:58 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-23229?
CVE-2024-23229 has been addressed with improvements and is considered a significant vulnerability impacting sensitive information.
2
How do I fix CVE-2024-23229?
To fix CVE-2024-23229, update your system to macOS Monterey 12.7.5, macOS Ventura 13.6.5, or macOS Sonoma 14.4.
3
Which versions of macOS are affected by CVE-2024-23229?
CVE-2024-23229 affects macOS versions before 12.7.5, 13.6.5, and 14.4.
4
What type of issue is CVE-2024-23229?
CVE-2024-23229 is an information disclosure vulnerability that may allow malicious applications to access sensitive data.
5
Who is the vendor for CVE-2024-23229?
The vendor for CVE-2024-23229 is Apple.