Researchers Detail Apple's Recent Zero-Click Shortcuts Vulnerability
ID: 47e27050-9751-5308-9bb5-2a7dc5b171eb
STIX ID: report--47e27050-9751-5308-9bb5-2a7dc5b171eb
Feed Name: The Hacker News
Apple patched CVE-2024-23204, a high-severity Shortcuts vulnerability (CVSS 7.5) that allowed malicious shortcuts to bypass TCC protections and exfiltrate sensitive data (Photos, Contacts, Files, clipboard) by using the 'Expand URL' action to Base64-encode selected data and send it to attacker-controlled servers; the flaw was demonstrated by a Bitdefender researcher and could spread via shared shortcuts, and fixes were released in iOS/iPadOS 17.3, macOS Sonoma 14.3, and watchOS 10.3.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
