CVE-2024-44274
Published Oct 28, 2024
·Updated
Accessibility. The issue was addressed with improved authentication.
Credit
Rizki Maulana (rmrizki.my.id), Matthew Butler, Jake Derouin, an anonymous researcher, Ivan Fratric(Google Project Zero), K宝@@Pwnrin, pattern-f@@pattern_F_(Loadshine Lab), Hikerell(Loadshine Lab), Hossein Lotfi@@hosselot(Trend Micro Zero Day Initiative), Junsung Lee(Trend Micro Zero Day Initiative), Jex Amro, Mateusz Krzywicki@@krzywix, Bing Shi(Alibaba Group), Wenchao Li(Alibaba Group), Xiaolong Bai(Alibaba Group), (Indiana University Bloomington), Luyi Xing(Indiana University Bloomington), Kirin@@Pwnrin, Rodolphe Brunetti@@eisw0lf, Wojciech Regula(SecuRing), Narendra Bhati(Cyber Security at Suma Soft Pvt), Manager(Cyber Security at Suma Soft Pvt), Pune (India), Q1IQ@@q1iqF, P1umer@@p1umer, Wang Yu(Cyberserval), Hichem Maloufi, Christian Mina, Ismail Amzdak, Nimrat Khalsa, James Gill @infosec.exchange)@@jjtech, Dragon Fruit Security (Davis Dai, ORAC Luoyun, Frank Du cooperative discovery), 냥냥, Michael DePlante@@izobashi(Trend Micro Zero Day Initiative), Bistrit Dahal, Kenneth Chew, Braylon@@softwarescool, Ye Zhang@@VAR10CK(Baidu Security), Ziyi Zhou Jiao Tong University)@@Shanghai, Tianxiao Hou Jiao Tong University)@@Shanghai, Ben Roeder, an anonymous researcher(Dawn Security Lab of JD), Yinyi Wu@@_3ndy1(Dawn Security Lab of JD), Lucas Di Tomase, Abhay Kailasia@@abhay_kailasia(Lakshmi Narain College of Technology Bhopal India), Srijan Poudel, 7feilee, Cristian Dinca (icmd.tech), Dalibor Milanovic, Richard Hyunho Im with Route Zero Security@@richeeta, Abhay Kailasia@@abhay_kailasia(C)
Affected Software
10 affected componentsFixes available
Apple WatchOS<11.1
11.1
Apple iOS<18.1
18.1
Apple iPadOS<18.1
18.1
Apple iOS<17.7.1
17.7.1
Apple iPadOS<17.7.1
17.7.1
Apple iPadOS<17.7.1
Apple iPadOS>=18.0<18.1
Apple iPhone OS<17.7.1
Apple iPhone OS>=18.0<18.1
Apple WatchOS<11.1
Event History
Oct 28, 2024
Data Sourced
via Apple·12:00 AM
DescriptionWeaknessAffected Software
Updated
via Apple·12:00 AM
Affected Software
CVE Published
via MITRE·09:07 PM
Data Sourced
via MITRE·09:07 PM
DescriptionWeakness
Data Sourced
via NVD·09:15 PM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-44274?
CVE-2024-44274 is considered a moderate severity vulnerability due to the requirement of physical access to the device.
2
How do I fix CVE-2024-44274?
To fix CVE-2024-44274, upgrade to iOS 17.7.1, iPadOS 17.7.1, watchOS 11.1, iOS 18.1 or iPadOS 18.1.
3
What type of devices are affected by CVE-2024-44274?
CVE-2024-44274 affects Apple iPhone, iPad, and watchOS devices running specific vulnerable versions.
4
What information could be exposed due to CVE-2024-44274?
CVE-2024-44274 may allow an attacker with physical access to view sensitive user information on the device.
5
When was CVE-2024-44274 reported?
CVE-2024-44274 was reported following the discovery of the vulnerability allowing unauthorized access to sensitive data.