CVE-2024-40840: Medium severity Apple iOS vulnerability
Accessibility. This issue was addressed through improved state management.
Other sources
This issue was addressed through improved state management. This issue is fixed in iOS 18 and iPadOS 18. An attacker with physical access may be able to use Siri to access sensitive user data.
— MITRE
Credit
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2024-40840
- CVE-2024-40830
- CVE-2024-44171
- CVE-2024-40852
- CVE-2024-44126
- CVE-2024-27874
- CVE-2024-27876
- CVE-2024-27869
- CVE-2024-44124
- CVE-2024-54469
- CVE-2024-44131
- CVE-2024-40850
- CVE-2024-27880
- CVE-2024-44176
- CVE-2024-44169
- CVE-2024-44165
- CVE-2024-44191
- CVE-2024-44122
- CVE-2024-54560
- CVE-2024-44198
- CVE-2024-40791
- CVE-2024-44183
- CVE-2023-5841
- CVE-2024-44147
- CVE-2024-44167
- CVE-2024-44217
- CVE-2024-40826
- CVE-2024-44155
- CVE-2024-44202
- CVE-2024-44127
- CVE-2024-40863
- CVE-2024-44144
- CVE-2024-44123
- CVE-2024-44145
- CVE-2024-44179
- CVE-2024-40853
- CVE-2024-44139
- CVE-2024-44180
- CVE-2024-44170
- CVE-2024-54558
- CVE-2024-44184
- CVE-2024-27879
- CVE-2024-54467
- CVE-2024-44192
- CVE-2024-40857
- CVE-2024-44187
- CVE-2024-44227
- CVE-2024-40856
Frequently Asked Questions
What is the severity of CVE-2024-40840?
CVE-2024-40840 is considered to have a medium severity due to the potential data access by attackers with physical access.
How do I fix CVE-2024-40840?
To fix CVE-2024-40840, update your device to iOS 18 or iPadOS 18 or later.
What is the impact of CVE-2024-40840?
The impact of CVE-2024-40840 is that an attacker with physical access could misuse Siri to access sensitive user data.
Is CVE-2024-40840 exploitable remotely?
No, CVE-2024-40840 requires physical access to the device for exploitation.
Which devices are affected by CVE-2024-40840?
CVE-2024-40840 affects devices running iOS prior to version 18 and iPadOS prior to version 18.