CVE-2024-40804: Infoleak
Published Jul 29, 2024
·Updated
Accounts. The issue was addressed with improved checks.
Credit
IES Red Team(ByteDance), Linwz(DEVCORE), Yeto, Csaba Fitzl@@theevilbit(Kandji), Mickey Jin@@patch1t, Michael DePlante@@izobashi(Trend Micro Zero Day Initiative), CertiK SkyFall Team, D4m0n, Amir Bazine(CrowdStrike Counter Adversary Operations), Karsten König(CrowdStrike Counter Adversary Operations), CVE-2024-2004, CVE-2024-2379, CVE-2024-2398, CVE-2024-2466, an anonymous researcher, Yann Gascuel(Alter Solutions), w0wbox, CVE-2023-6277, CVE-2023-52356, Yisumi, Junsung Lee(Trend Micro Zero Day Initiative), (CrowdStrike Counter Adversary Operations), Gandalf4a, Wang Yu(Cyberserval), Ye Zhang@@VAR10CK(Baidu Security), sqrtpwn, Minghao Lin(Zhejiang University), Jiaxun Zhu(Zhejiang University), Patrick Wardle(DoubleYou), CVE-2024-40805, Rodolphe BRUNETTI@@eisw0lf, Adam M., CVE-2024-6387, Pedro Tôrres@@t0rr3sp3dr0, Zhongquan Li@@Guluisacat(Dawn Security Lab of JingDong), Mickey Jin@@patch1t(Kandji), (Kandji), Mateen Alinaghi, Claudio Bozzato(Cisco Talos), Francesco Benvenuto(Cisco Talos), Csaba Fitzl@@theevilbit(Offensive Security), Yadhu Krishna M(Cyber Security At Suma Soft Pvt), Narendra Bhati(Cyber Security At Suma Soft Pvt), Manager(Cyber Security At Suma Soft Pvt), Pune (India), Wojciech Regula(SecuRing), (Dawn Security Lab of JingDong), Kirin@@Pwnrin, Joshua Jones, Jiwon Park, Marcio Almeida(Tanto Security), Bistrit Dahal, Srijan Poudel, Jiahui Hu (梅零落)(NorthSea), Meng Zhang (鲸落)(NorthSea), Arsenii Kostromin (0x3c3e), ajajfxhj, Huang Xilin(Ant Group Light), Maksymilian Motyl, Johan Carlsson (joaxcar), Seunghyun Lee@@0x10n(KAIST Hacking Lab working with Trend Micro Zero Day Initiative), CVE-2024-4558, Matthew Butler, Gary Kwong, Andreas Jaegersberger, Ro Achterberg
Affected Software
2 affected componentsFixes available
Apple macOS<14.6
14.6
macOS<14.6
Event History
Jul 29, 2024
CVE Published
via MITRE·10:17 PM
Data Sourced
via MITRE·10:17 PM
DescriptionWeakness
Data Sourced
via NVD·11:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-40804?
CVE-2024-40804 is considered a moderate severity vulnerability due to its potential to allow unauthorized access to private information.
2
How do I fix CVE-2024-40804?
To fix CVE-2024-40804, upgrade to macOS Sonoma version 14.6 or later.
3
What type of systems are affected by CVE-2024-40804?
CVE-2024-40804 affects macOS versions prior to 14.6.
4
What specific issue does CVE-2024-40804 address?
CVE-2024-40804 addresses the issue of a malicious application potentially accessing private information due to insufficient checks.
5
Is there a workaround for CVE-2024-40804?
There is no documented workaround for CVE-2024-40804; updating your system is the recommended action.