Skip to content

Threat Research Knowledge Base

CVE-2024-27821

Description

CVE-2024-27821 is a path handling issue within Apple's Shortcuts app. A flaw in the validation process could allow a shortcut to output sensitive user data without consent. Apple addressed this vulnerability by implementing improved validation mechanisms in macOS Sonoma 14.5, iOS 17.5, iPadOS 17.5, and watchOS 10.5.

Get a Free Trial

Impact

Exploitation of this vulnerability could lead to unauthorized disclosure of sensitive user information. The severity of this issue has been assessed as follows:

NIST assessment

CVSS v3.1 Base Score: 4.7 (Medium)

AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N

CISA-ADP assessment

CVSS v3.1 Base Score: 7.5 (High)

AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Has been exploited in the wild

No

Operating systems impacted

  • macOS Sonoma (prior to 14.5)
  • iOS (prior to 17.5)
  • iPadOS (prior to 17.5)
  • watchOS (prior to 10.5)

Apps impacted

No apps impacted

Related

Exploitation of this vulnerability could lead to unauthorized modification of protected file system areas by a malicious application. The severity of this issue has been assessed as follows:

Exploitation of this vulnerability could lead to unauthorized access to sensitive user data by an application. The severity of this issue has been assessed as follows:

Exploitation of this vulnerability could lead to unauthorized elevation of privileges by a malicious application. The severity of this issue has been assessed as follows:

Manage and secure your Apple devices at scale.

Laptop and 2 popup windows