CVE-2024-40822
8Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 2.4epss 0.4%
exploitation probability
0.4%top 67% of all CVEs
observed exploitation
nono source reports it
This issue was addressed by restricting options offered on a locked device. This issue is fixed in iOS 16.7.9 and iPadOS 16.7.9, iOS 17.6 and iPadOS 17.6, macOS Sonoma 14.6, watchOS 10.6. An attacker with physical access to a device may be able to access contacts from the lock screen.
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
References
http://seclists.org/fulldisclosure/2024/Jul/16http://seclists.org/fulldisclosure/2024/Jul/17http://seclists.org/fulldisclosure/2024/Jul/18http://seclists.org/fulldisclosure/2024/Jul/21https://support.apple.com/en-us/120908https://support.apple.com/en-us/120909https://support.apple.com/en-us/120911https://support.apple.com/en-us/120916https://support.apple.com/en-us/HT214116https://support.apple.com/en-us/HT214117https://support.apple.com/en-us/HT214119https://support.apple.com/en-us/HT214124