Skip to content

Threat Research Knowledge Base

CVE-2024-40783

Description

CVE-2024-40783 is a security vulnerability in Apple's macOS that could allow a malicious application to bypass Privacy preferences. The issue was addressed by Apple through improved restriction of data container access in macOS Sonoma 14.6, macOS Ventura 13.6.8, and macOS Monterey 12.7.6.

Get a Free Trial

Impact

Exploitation of this vulnerability could lead to unauthorized access to sensitive user data by bypassing Privacy preferences. The severity of this issue has been assessed as follows:

NIST assessment

CVSS v3.1 Base Score: 5.5 (Medium)

AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N

CISA-ADP assessment

CVSS v3.1 Base Score: 7.1 (High)

AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N

Has been exploited in the wild

No

Operating systems impacted

  • macOS Sonoma (prior to 14.6)
  • macOS Ventura (prior to 13.6.8)
  • macOS Monterey (prior to 12.7.6)

Apps impacted

No apps impacted

Related

Exploitation of this vulnerability could lead to unauthorized elevation of privileges by a malicious application. The severity of this issue has been assessed as follows:

Exploitation of this vulnerability could lead to unauthorized modification of protected file system areas by an application. The severity of this issue has been assessed as follows:

Exploitation of this vulnerability could lead to unauthorized access to sensitive location information by an application. The severity of this issue has been assessed as follows:

Manage and secure your Apple devices at scale.

Laptop and 2 popup windows