CVE-2024-40791: Race Condition
A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in iOS 17.7 and iPadOS 17.7, iOS 18 and iPadOS 18, macOS Sequoia 15, macOS Sonoma 14.7, macOS Ventura 13.7. An app may be able to access information about a user's contacts.
Other sources
Accessibility. This issue was addressed by restricting options offered on a locked device.
— Apple
Accessibility. This issue was addressed through improved state management.
— Apple
Accessibility. This issue was addressed with improved data protection.
— Apple
Accounts. A permissions issue was addressed with additional restrictions.
— Apple
Accounts. The issue was addressed with improved checks.
— Apple
Credit
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2024-44153
- CVE-2024-44182
- CVE-2024-40846
- CVE-2024-40845
- CVE-2024-44154
- CVE-2024-40847
- CVE-2024-44164
- CVE-2024-44168
- CVE-2024-40848
- CVE-2024-40841
- CVE-2024-44135
- CVE-2024-44126
- CVE-2024-44128
- CVE-2024-44151
- CVE-2024-27876
- CVE-2024-44177
- CVE-2024-54469
- CVE-2024-40850
- CVE-2024-27880
- CVE-2024-44176
- CVE-2024-44160
- CVE-2024-44161
- CVE-2024-44169
- CVE-2024-44165
- CVE-2024-40791
- CVE-2024-44181
- CVE-2024-44183
- CVE-2024-44167
- CVE-2024-44178
- CVE-2024-40797
- CVE-2024-44163
- CVE-2024-44125
- CVE-2024-40801
- CVE-2024-44158
- CVE-2024-40844
- CVE-2024-40860
- CVE-2024-44166
- CVE-2024-44190
- CVE-2024-44184
- CVE-2024-40840
- CVE-2024-40830
- CVE-2024-44171
- CVE-2024-40852
- CVE-2024-27874
- CVE-2024-27869
- CVE-2024-44124
- CVE-2024-44131
- CVE-2024-44191
- CVE-2024-44122
- CVE-2024-54560
- CVE-2024-44198
- CVE-2023-5841
- CVE-2024-44147
- CVE-2024-44217
- CVE-2024-40826
- CVE-2024-44155
- CVE-2024-44202
- CVE-2024-44127
- CVE-2024-40863
- CVE-2024-44144
- CVE-2024-44123
- CVE-2024-44145
- CVE-2024-44179
- CVE-2024-40853
- CVE-2024-44139
- CVE-2024-44180
- CVE-2024-44170
- CVE-2024-54558
- CVE-2024-27879
- CVE-2024-54467
- CVE-2024-44192
- CVE-2024-40857
- CVE-2024-44187
- CVE-2024-44227
- CVE-2024-40856
- CVE-2024-44129
- CVE-2024-27886
- CVE-2024-40814
- CVE-2024-44188
- CVE-2024-40792
- CVE-2024-40825
- CVE-2024-44130
- CVE-2024-40837
- CVE-2024-27860
- CVE-2024-27861
- CVE-2024-27795
- CVE-2024-44132
- CVE-2024-44172
- CVE-2024-27875
- CVE-2024-44146
- CVE-2024-27849
- CVE-2023-4504
- CVE-2024-40855
- CVE-2024-44148
- CVE-2024-54463
- CVE-2024-40831
- CVE-2024-40861
- CVE-2024-44175
- CVE-2024-54473
- CVE-2024-27858
- CVE-2024-40838
- CVE-2024-44186
- CVE-2024-39894
- CVE-2024-44149
- CVE-2024-44203
- CVE-2024-44137
- CVE-2024-44174
- CVE-2024-44152
- CVE-2024-44133
- CVE-2024-40859
- CVE-2024-41957
- CVE-2024-40866
- CVE-2024-54546
- CVE-2024-40770
- CVE-2024-23237
- CVE-2024-44134
- CVE-2024-44189
- CVE-2024-44208
- CVE-2024-40842
- CVE-2024-40843
Frequently Asked Questions
What is the severity of CVE-2024-40791?
The severity of CVE-2024-40791 is considered high due to potential unauthorized access to sensitive user contact information.
What software versions are affected by CVE-2024-40791?
CVE-2024-40791 affects iPadOS versions up to 17.7, iPhone OS versions up to 17.7, macOS versions up to 13.7, and macOS versions between 14.0 and 14.7.
How do I fix CVE-2024-40791?
To fix CVE-2024-40791, you should update your iPadOS, iPhone OS, or macOS to the latest versions: iOS 18, iPadOS 18, macOS Ventura 13.7, macOS Sonoma 14.7, or macOS Sequoia 15.
What kind of data is compromised in CVE-2024-40791?
CVE-2024-40791 can potentially expose private user contact information through inadequate log entry redaction.
Is there a workaround for CVE-2024-40791 before updating?
There are currently no documented workarounds for CVE-2024-40791, making immediate software updates the recommended approach.