CVE-2024-44217

A permissions issue was addressed by removing vulnerable code and adding additional checks. This issue is fixed in iOS 18 and iPadOS 18. Password autofill may fill in passwords after failing authentication.
References
Link Resource
https://support.apple.com/en-us/121250 Vendor Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*

History

12 Dec 2024, 19:55

Type Values Removed Values Added
CWE CWE-863
CPE cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.1
First Time Apple ipados
Apple
Apple iphone Os
References () https://support.apple.com/en-us/121250 - () https://support.apple.com/en-us/121250 - Vendor Advisory

28 Oct 2024, 22:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-10-28 22:15

Updated : 2024-12-12 19:55


NVD link : CVE-2024-44217

Mitre link : CVE-2024-44217


JSON object : View

Products Affected

apple

  • ipados
  • iphone_os
CWE
CWE-863

Incorrect Authorization