Threat Research Knowledge Base Vulnerabilities CVE-2024-40795
CVE-2024-40795
Description
CVE-2024-40795 is a security vulnerability in Apple's Family Sharing component that could allow an application to read sensitive location information. The issue was addressed by Apple through improved data protection in macOS Sonoma 14.6, iOS 17.6, iPadOS 17.6, watchOS 10.6, and tvOS 17.6. The vulnerability was discovered by Csaba Fitzl (@theevilbit) of Kandji.
Impact
Exploitation of this vulnerability could lead to unauthorized access to sensitive location information by an application. The severity of this issue has been assessed as follows:
NIST assessment
CVSS v3.1 Base Score: 3.3 (Low)
AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
CISA-ADP assessment
CVSS v3.1 Base Score: 3.3 (Low)
AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Has been exploited in the wild
No
Operating systems impacted
- macOS Sonoma (prior to 14.6)
- iOS (prior to 17.6)
- iPadOS (prior to 17.6)
- watchOS (prior to 10.6)
- tvOS (prior to 17.6)
Additional resources
Apps impacted
No apps impacted
Related
Exploitation of this vulnerability could lead to unauthorized elevation of privileges by a malicious application. The severity of this issue has been assessed as follows:
Exploitation of this vulnerability could lead to unauthorized access to sensitive user data by bypassing Privacy preferences. The severity of this issue has been assessed as follows:
Exploitation of this vulnerability could lead to unauthorized access to sensitive user data by a sandboxed application. The severity of this issue has been assessed as follows:
Manage and secure your Apple devices at scale.
