Zero-Click Apple Shortcuts Vulnerability Allows Silent Data Theft
ID: d91ba3dc-29a5-54db-811c-a797fb805531
STIX ID: report--d91ba3dc-29a5-54db-811c-a797fb805531
Feed Name: Dark Reading
A serious vulnerability (CVE-2024-23204) in Apple Shortcuts allowed crafted shortcuts to bypass Apple's Transparency, Consent, and Control (TCC) protections and silently access and exfiltrate sensitive data on devices running versions prior to macOS Sonoma 14.3, iOS 17.3, and iPadOS 17.3; Bitdefender published a proof-of-concept demonstrating data theft (encrypted into an image), the flaw is scored CVSS 7.5 (High), and Apple has issued a patch—users are urged to update and avoid running shortcuts from untrusted sources.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
