CVE-2024-40852: High severity Apple iOS and iPadOS vulnerability
Accessibility. This issue was addressed by restricting options offered on a locked device.
Other sources
Accessibility. This issue was addressed through improved state management.
— Apple
Accessibility. This issue was addressed with improved data protection.
— Apple
This issue was addressed by restricting options offered on a locked device. This issue is fixed in iOS 18 and iPadOS 18. An attacker may be able to see recent photos without authentication in Assistive Access.
— MITRE
Credit
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2024-40840
- CVE-2024-40830
- CVE-2024-44171
- CVE-2024-40852
- CVE-2024-44126
- CVE-2024-27874
- CVE-2024-27876
- CVE-2024-27869
- CVE-2024-44124
- CVE-2024-54469
- CVE-2024-44131
- CVE-2024-40850
- CVE-2024-27880
- CVE-2024-44176
- CVE-2024-44169
- CVE-2024-44165
- CVE-2024-44191
- CVE-2024-44122
- CVE-2024-54560
- CVE-2024-44198
- CVE-2024-40791
- CVE-2024-44183
- CVE-2023-5841
- CVE-2024-44147
- CVE-2024-44167
- CVE-2024-44217
- CVE-2024-40826
- CVE-2024-44155
- CVE-2024-44202
- CVE-2024-44127
- CVE-2024-40863
- CVE-2024-44144
- CVE-2024-44123
- CVE-2024-44145
- CVE-2024-44179
- CVE-2024-40853
- CVE-2024-44139
- CVE-2024-44180
- CVE-2024-44170
- CVE-2024-54558
- CVE-2024-44184
- CVE-2024-27879
- CVE-2024-54467
- CVE-2024-44192
- CVE-2024-40857
- CVE-2024-44187
- CVE-2024-44227
- CVE-2024-40856
Frequently Asked Questions
What is the severity of CVE-2024-40852?
CVE-2024-40852 has been classified with a severity that indicates potential risks associated with accessibility features in Apple devices.
How do I fix CVE-2024-40852?
To fix CVE-2024-40852, users should update their Apple iOS or iPadOS to version 18 or later.
What devices are affected by CVE-2024-40852?
CVE-2024-40852 affects Apple devices running iOS and iPadOS versions prior to 18.0.
What type of issue does CVE-2024-40852 address?
CVE-2024-40852 addresses accessibility vulnerabilities that could affect data protection and state management.
Is CVE-2024-40852 related to device security?
Yes, CVE-2024-40852 is related to device security by addressing potential risks when using accessibility options on locked devices.