logo

Zero-Click RCE Bug in macOS Calendar Exposes iCloud Data

ID: b95459e8-dd77-5f41-b078-fcd6df70c71b

STIX ID: report--b95459e8-dd77-5f41-b078-fcd6df70c71b

Feed Name: Dark Reading

Threat Score
70/100

Date Published: 2024-09-17

Date Updated: 2026-04-21

Author: Nate Nelson, Contributing Writer

...
...

A researcher demonstrated a zero-click exploit chain in macOS Calendar that used a critical arbitrary file-write bug (CVE-2022-46723) to achieve remote code execution, then bypass Gatekeeper (CVE-2023-40344) and TCC protections (CVE-2023-40434), allowing iCloud Photos to be re-pointed and exfiltrated; Apple patched the vulnerabilities between October 2022 and September 2023.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.