Threat Research Knowledge Base Vulnerabilities CVE-2024-27821
CVE-2024-27821
Description
CVE-2024-27821 is a path handling issue within Apple's Shortcuts app. A flaw in the validation process could allow a shortcut to output sensitive user data without consent. Apple addressed this vulnerability by implementing improved validation mechanisms in macOS Sonoma 14.5, iOS 17.5, iPadOS 17.5, and watchOS 10.5.
Impact
Exploitation of this vulnerability could lead to unauthorized disclosure of sensitive user information. The severity of this issue has been assessed as follows:
NIST assessment
CVSS v3.1 Base Score: 4.7 (Medium)
AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N
CISA-ADP assessment
CVSS v3.1 Base Score: 7.5 (High)
AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Has been exploited in the wild
No
Operating systems impacted
- macOS Sonoma (prior to 14.5)
- iOS (prior to 17.5)
- iPadOS (prior to 17.5)
- watchOS (prior to 10.5)
Additional resources
Apps impacted
No apps impacted
Related
Exploitation of this vulnerability could lead to unauthorized modification of protected file system areas by a malicious application. The severity of this issue has been assessed as follows:
Exploitation of this vulnerability could lead to unauthorized access to sensitive user data by an application. The severity of this issue has been assessed as follows:
Exploitation of this vulnerability could lead to unauthorized elevation of privileges by a malicious application. The severity of this issue has been assessed as follows:
Manage and secure your Apple devices at scale.
