logo

Researchers Detail Apple's Recent Zero-Click Shortcuts Vulnerability

ID: 47e27050-9751-5308-9bb5-2a7dc5b171eb

STIX ID: report--47e27050-9751-5308-9bb5-2a7dc5b171eb

Feed Name: The Hacker News

Threat Score
70/100

Date Published: 2024-02-23

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

Apple patched CVE-2024-23204, a high-severity Shortcuts vulnerability (CVSS 7.5) that allowed malicious shortcuts to bypass TCC protections and exfiltrate sensitive data (Photos, Contacts, Files, clipboard) by using the 'Expand URL' action to Base64-encode selected data and send it to attacker-controlled servers; the flaw was demonstrated by a Bitdefender researcher and could spread via shared shortcuts, and fixes were released in iOS/iPadOS 17.3, macOS Sonoma 14.3, and watchOS 10.3.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.