CVE-2024-40838: Input Validation
A privacy issue was addressed by moving sensitive data to a protected location. This issue is fixed in macOS Sequoia 15. A malicious app may be able to access notifications from the user's device.
Other sources
Accounts. A permissions issue was addressed with additional restrictions.
— Apple
Accounts. The issue was addressed with improved checks.
— Apple
Accounts. The issue was addressed with improved permissions logic.
— Apple
Airport. A permissions issue was addressed with additional restrictions.
— Apple
APFS. The issue was addressed with improved checks.
— Apple
Credit
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2024-44129
- CVE-2024-44153
- CVE-2024-44188
- CVE-2024-40792
- CVE-2024-40825
- CVE-2024-44130
- CVE-2024-44182
- CVE-2024-44154
- CVE-2024-40845
- CVE-2024-40846
- CVE-2024-44164
- CVE-2024-40837
- CVE-2024-40847
- CVE-2024-40848
- CVE-2024-44168
- CVE-2024-27860
- CVE-2024-27861
- CVE-2024-40841
- CVE-2024-27795
- CVE-2024-44135
- CVE-2024-44132
- CVE-2024-44126
- CVE-2024-44128
- CVE-2024-44151
- CVE-2024-27876
- CVE-2024-44172
- CVE-2024-27869
- CVE-2024-27875
- CVE-2024-44146
- CVE-2024-27849
- CVE-2023-4504
- CVE-2024-40855
- CVE-2024-44148
- CVE-2024-44177
- CVE-2024-54469
- CVE-2024-44131
- CVE-2024-40850
- CVE-2024-54463
- CVE-2024-40831
- CVE-2024-27880
- CVE-2024-44176
- CVE-2024-40861
- CVE-2024-44160
- CVE-2024-44161
- CVE-2024-44169
- CVE-2024-44165
- CVE-2024-44175
- CVE-2024-44191
- CVE-2024-54560
- CVE-2024-44122
- CVE-2024-44198
- CVE-2024-40791
- CVE-2024-54473
- CVE-2024-44181
- CVE-2024-44183
- CVE-2023-5841
- CVE-2024-27858
- CVE-2024-44167
- CVE-2024-40838
- CVE-2024-44186
- CVE-2024-39894
- CVE-2024-44178
- CVE-2024-40826
- CVE-2024-44149
- CVE-2024-40797
- CVE-2024-44155
- CVE-2024-44125
- CVE-2024-44163
- CVE-2024-44203
- CVE-2024-44144
- CVE-2024-44137
- CVE-2024-44174
- CVE-2024-44123
- CVE-2024-40801
- CVE-2024-44158
- CVE-2024-40844
- CVE-2024-44145
- CVE-2024-44179
- CVE-2024-44170
- CVE-2024-40860
- CVE-2024-44152
- CVE-2024-44166
- CVE-2024-44190
- CVE-2024-54558
- CVE-2024-44133
- CVE-2024-44184
- CVE-2024-40859
- CVE-2024-41957
- CVE-2024-54467
- CVE-2024-44192
- CVE-2024-40857
- CVE-2024-40866
- CVE-2024-44187
- CVE-2024-44227
- CVE-2024-54546
- CVE-2024-40770
- CVE-2024-23237
- CVE-2024-44134
- CVE-2024-40856
- CVE-2024-44189
- CVE-2024-44208
- CVE-2024-40842
- CVE-2024-40843
Frequently Asked Questions
What is the severity of CVE-2024-40838?
CVE-2024-40838 is considered a medium-severity vulnerability due to its potential impact on user privacy.
How do I fix CVE-2024-40838?
To fix CVE-2024-40838, update your macOS to Sequoia 15 or later.
What systems are impacted by CVE-2024-40838?
CVE-2024-40838 affects all versions of macOS prior to Sequoia 15.
What kind of data may be exposed due to CVE-2024-40838?
CVE-2024-40838 may allow malicious apps to access sensitive user notifications.
Is there a workaround for CVE-2024-40838?
There is no recommended workaround for CVE-2024-40838 other than upgrading to the latest macOS version.