CVE-2024-44217

A permissions issue was addressed by removing vulnerable code and adding additional checks. This issue is fixed in iOS 18 and iPadOS 18. Password autofill may fill in passwords after failing authentication.
References
Link Resource
https://support.apple.com/en-us/121250 Vendor Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*

History

12 Dec 2024, 19:55

Type Values Removed Values Added
References () https://support.apple.com/en-us/121250 - () https://support.apple.com/en-us/121250 - Vendor Advisory
First Time Apple
Apple iphone Os
Apple ipados
CWE CWE-863
CPE cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*

29 Oct 2024, 20:35

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.1

29 Oct 2024, 14:34

Type Values Removed Values Added
Summary
  • (es) Se solucionó un problema de permisos eliminando el código vulnerable y agregando comprobaciones adicionales. Este problema se solucionó en iOS 18 y iPadOS 18. El autocompletado de contraseñas puede completar las contraseñas después de una autenticación fallida.

28 Oct 2024, 22:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-10-28 22:15

Updated : 2024-12-12 19:55


NVD link : CVE-2024-44217

Mitre link : CVE-2024-44217

CVE.ORG link : CVE-2024-44217


JSON object : View

Products Affected

apple

  • ipados
  • iphone_os
CWE
CWE-863

Incorrect Authorization