Details on Apple’s Shortcuts Vulnerability: A Deep Dive into CVE-2024-23204
ID: a9895229-1fb1-591b-a2d5-36773c3a92e5
STIX ID: report--a9895229-1fb1-591b-a2d5-36773c3a92e5
Feed Name: Bitdefender Labs
This report describes CVE-2024-23204, a High-severity vulnerability (CVSS 7.5) in Apple Shortcuts that can be abused to bypass Apple's TCC permission prompts—using the 'Expand URL' action to base64-encode and exfiltrate sensitive data (photos, contacts, files, clipboard) to an attacker-controlled server; affected devices running macOS prior to Sonoma 14.3 and iOS/iPadOS prior to 17.3 are fixed by Apple updates, and users are advised to update and avoid installing shortcuts from untrusted sources.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
