CVE-2024-44171: Medium severity Apple WatchOS vulnerability
Accessibility. This issue was addressed through improved state management.
Other sources
Accessibility. This issue was addressed with improved data protection.
— Apple
This issue was addressed through improved state management. This issue is fixed in iOS 17.7 and iPadOS 17.7, iOS 18 and iPadOS 18, watchOS 11. An attacker with physical access to a locked device may be able to Control Nearby Devices via accessibility features.
— MITRE
Credit
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2024-44171
- CVE-2024-40850
- CVE-2024-27880
- CVE-2024-44176
- CVE-2024-44169
- CVE-2024-44191
- CVE-2024-54560
- CVE-2024-44198
- CVE-2024-44183
- CVE-2024-44155
- CVE-2024-44144
- CVE-2024-44170
- CVE-2024-54467
- CVE-2024-44192
- CVE-2024-40857
- CVE-2024-44187
- CVE-2024-40840
- CVE-2024-40830
- CVE-2024-40852
- CVE-2024-44126
- CVE-2024-27874
- CVE-2024-27876
- CVE-2024-27869
- CVE-2024-44124
- CVE-2024-54469
- CVE-2024-44131
- CVE-2024-44165
- CVE-2024-44122
- CVE-2024-40791
- CVE-2023-5841
- CVE-2024-44147
- CVE-2024-44167
- CVE-2024-44217
- CVE-2024-40826
- CVE-2024-44202
- CVE-2024-44127
- CVE-2024-40863
- CVE-2024-44123
- CVE-2024-44145
- CVE-2024-44179
- CVE-2024-40853
- CVE-2024-44139
- CVE-2024-44180
- CVE-2024-54558
- CVE-2024-44184
- CVE-2024-27879
- CVE-2024-44227
- CVE-2024-40856
- CVE-2024-44158
- CVE-2024-40844
- CVE-2024-44164
Frequently Asked Questions
What is the severity of CVE-2024-44171?
CVE-2024-44171 is considered a high severity vulnerability that could allow an attacker with physical access to control nearby devices.
How do I fix CVE-2024-44171?
To fix CVE-2024-44171, update to iOS 17.7, iPadOS 17.7, iOS 18, iPadOS 18, or watchOS 11.
What devices are affected by CVE-2024-44171?
CVE-2024-44171 affects iPadOS versions prior to 17.7, iPhone OS versions prior to 17.7, and watchOS versions prior to 11.0.
Can CVE-2024-44171 be exploited remotely?
No, CVE-2024-44171 requires physical access to the locked device to exploit.
What does CVE-2024-44171 involve?
CVE-2024-44171 involves insufficient state management that may allow control of nearby devices through accessibility features.