logo

Apple Shortcuts Vulnerability Exposes Sensitive Data, Update Now!

ID: 3af15410-0792-57ac-b040-2f37da62d09a

STIX ID: report--3af15410-0792-57ac-b040-2f37da62d09a

Feed Name: HackRead

Threat Score
65/100

Date Published: 2024-02-22

Date Updated: 2026-04-22

Author: Waqas

...
...

Bitdefender disclosed CVE-2024-23204, a 7.5/10 severity vulnerability in Apple Shortcuts that can bypass macOS/iOS Transparency, Consent, and Control (TCC) protections by abusing the 'Expand URL' action to base64-encode and transmit sensitive data (e.g., photos) to an attacker-controlled server; Apple has released fixes in iOS/iPadOS 17.3, macOS Sonoma 14.3, and watchOS 10.3, and users are advised to update devices and avoid importing shortcuts from untrusted sources.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.