logo

Details on Apple’s Shortcuts Vulnerability: A Deep Dive into CVE-2024-23204

ID: a9895229-1fb1-591b-a2d5-36773c3a92e5

STIX ID: report--a9895229-1fb1-591b-a2d5-36773c3a92e5

Feed Name: Bitdefender Labs

Threat Score
70/100

Date Published: 2024-02-22

Date Updated: 2026-04-27

Author: Jubaer Alnazi JABIN

...
...

This report describes CVE-2024-23204, a High-severity vulnerability (CVSS 7.5) in Apple Shortcuts that can be abused to bypass Apple's TCC permission prompts—using the 'Expand URL' action to base64-encode and exfiltrate sensitive data (photos, contacts, files, clipboard) to an attacker-controlled server; affected devices running macOS prior to Sonoma 14.3 and iOS/iPadOS prior to 17.3 are fixed by Apple updates, and users are advised to update and avoid installing shortcuts from untrusted sources.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.