CVE-2024-27886

Published Mar 7, 2024
·
Updated

A logic issue was addressed with improved restrictions. This issue is fixed in macOS Sonoma 14.4, macOS Ventura 13.7. An unprivileged app may be able to log keystrokes in other apps including those using secure input mode.

Credit

Stephan Casas, an anonymous researcher, Kirin@@Pwnrin, Brian McNulty, Mickey Jin@@patch1t, Wojciech Regula(SecuRing), Marc Newlin(SkySafe), m4yfly with TianGong Team(Legendsec at Qi'anxin Group), Guilherme Rambo(Best Buddy Apps), Csaba Fitzl@@theevilbit(OffSec), CVE-2024-23205, CVE-2022-48554, Joshua Jewett@@JoshJewett33, Junsung Lee(Trend Micro Zero Day Initiative), Zhenjiang Zhao(pangu team), Qianxin(CrowdStrike Counter Adversary Operations), (CrowdStrike Counter Adversary Operations), Amir Bazine(CrowdStrike Counter Adversary Operations), Karsten König(CrowdStrike Counter Adversary Operations), Dohyun Lee@@l33d0hyun, Lyutoon, Mr.R, Murray Mike, Pedro Tôrres@@t0rr3sp3dr0, CVE-2024-23235, Xinru Chi(Pangu Lab), CVE-2024-23225, koocola, ali yabuz, Meysam Firouzi@@R00tkitsmm(Trend Micro Zero Day Initiative), @@08Tc3wBB(Jamf), CVE-2024-23283, CVE-2023-48795, CVE-2023-51384, CVE-2023-51385, Bohdan Stasiuk@@Bohdan_Stasiuk, Harsh Tyagi, CVE-2024-23296, Lyra Rebane (rebane2001), Matej Rabzelj, CVE-2024-23238, Yiğit Can YILMAZ@@yilmazcanyigit, luckyu@@uuulucky, K宝(Fudan University), LFY@@secsys(Fudan University), Lewis Hardy, Bistrit Dahal, CVE-2024-23241, CVE-2024-23242, Matthew Loewen, Deutsche Telekom Security GmbH sponsored by Bundesamt für Sicherheit in der Informationstechnik, anbu1024(SecANT), Pwn2car, James Lee@@Windowsrcer, Johan Carlsson (joaxcar), Georg Felber, Marco Squarcina, CVE-2024-23291, Claudio Bozzato(Cisco Talos), Francesco Benvenuto(Cisco Talos), Anton Boegler, Snoolie Keffaber@@0xilis, Csaba Fitzl@@theevilbit(Kandji), Denis Tokarev@@illusionofcha0s, dw0r(ZeroPointer Lab working with Trend Micro Zero Day Initiative), Michael DePlante@@izobashi(Trend Micro Zero Day Initiative), Antonio Zekić, Andrew Lytvynov, Rodolphe BRUNETTI@@eisw0lf, Kirin@@Pwnrin(Fudan University), Olivier Levon, ajajfxhj, Rifa'i Rejal Maynando, Zhongquan Li@@Guluisacat, Kirin@@Pwnrin(NorthSea), luckyu@@uuulucky(NorthSea), CVE-2024-44129

Affected Software

3 affected componentsFixes available
Apple macOS<14.4
14.4
macOS>=14.0<14.4
macOS Ventura<13.7
13.7

Event History

Jul 29, 2024
CVE Published
via MITRE·10:16 PM
Data Sourced
via MITRE·10:16 PM
DescriptionWeakness
Data Sourced
via NVD·11:15 PM
DescriptionSeverityWeaknessAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2024-27886?

CVE-2024-27886 is considered a high severity vulnerability due to its potential for unauthorized keystroke logging.

2

How do I fix CVE-2024-27886?

To fix CVE-2024-27886, upgrade to macOS Sonoma version 14.4 or later.

3

What does CVE-2024-27886 affect?

CVE-2024-27886 affects macOS versions from 14.0 up to, but not including, 14.4.

4

Can CVE-2024-27886 impact secure input mode?

Yes, CVE-2024-27886 may allow unprivileged apps to log keystrokes even in secure input mode.

5

What type of issue is CVE-2024-27886?

CVE-2024-27886 is classified as a logic issue that was fixed with improved restrictions.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203