CVE-2024-44274: Medium severity Apple WatchOS vulnerability
Accessibility. The issue was addressed with improved authentication.
Other sources
The issue was addressed with improved authentication. This issue is fixed in iOS 17.7.1 and iPadOS 17.7.1, iOS 18.1 and iPadOS 18.1, watchOS 11.1. An attacker with physical access to a locked device may be able to view sensitive user information.
— MITRE
Credit
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2024-44274
- CVE-2024-44255
- CVE-2024-44232
- CVE-2024-44233
- CVE-2024-44234
- CVE-2024-54535
- CVE-2024-44273
- CVE-2024-44240
- CVE-2024-44302
- CVE-2024-44282
- CVE-2024-44215
- CVE-2024-44297
- CVE-2024-44285
- CVE-2024-44239
- CVE-2024-54538
- CVE-2024-44254
- CVE-2024-44269
- CVE-2024-44194
- CVE-2024-44278
- CVE-2024-44290
- CVE-2024-44212
- CVE-2024-44296
- CVE-2024-44244
- CVE-2024-40854
- CVE-2024-44258
- CVE-2024-44252
- CVE-2024-44155
- CVE-2024-44259
- CVE-2024-44144
- CVE-2024-44218
- CVE-2024-54470
- CVE-2024-44261
- CVE-2024-44299
- CVE-2024-44241
- CVE-2024-44242
- CVE-2024-44238
- CVE-2024-40867
- CVE-2024-44201
- CVE-2024-44277
- CVE-2024-44229
- CVE-2024-40851
- CVE-2024-44263
- CVE-2024-44200
- CVE-2024-44251
- CVE-2024-44235
- CVE-2024-54556
Frequently Asked Questions
What is the severity of CVE-2024-44274?
CVE-2024-44274 is considered a moderate severity vulnerability due to the requirement of physical access to the device.
How do I fix CVE-2024-44274?
To fix CVE-2024-44274, upgrade to iOS 17.7.1, iPadOS 17.7.1, watchOS 11.1, iOS 18.1 or iPadOS 18.1.
What type of devices are affected by CVE-2024-44274?
CVE-2024-44274 affects Apple iPhone, iPad, and watchOS devices running specific vulnerable versions.
What information could be exposed due to CVE-2024-44274?
CVE-2024-44274 may allow an attacker with physical access to view sensitive user information on the device.
When was CVE-2024-44274 reported?
CVE-2024-44274 was reported following the discovery of the vulnerability allowing unauthorized access to sensitive data.