logo

Details on Apple’s Shortcuts Vulnerability: A Deep Dive into CVE-2024-23204

ID: c079cf2f-8532-56d2-b7af-69b55e52b869

STIX ID: report--c079cf2f-8532-56d2-b7af-69b55e52b869

Feed Name: Bitdefender Labs

Threat Score
70/100

Date Published: 2024-02-22

Date Updated: 2026-04-27

Author: Jubaer Alnazi JABIN

...
...

CVE-2024-23204 is a high-severity vulnerability in Apple Shortcuts that could allow a maliciously crafted shortcut using the 'Expand URL' action to bypass Transparency, Consent, and Control (TCC) prompts and exfiltrate sensitive data (photos, contacts, files, clipboard) by base64-encoding content and sending it to an attacker-controlled server; it has a CVSS score of 7.5, affected macOS and iOS/iPadOS versions prior to Sonoma 14.3 and 17.3, and has been addressed by Apple—users should apply updates and avoid running shortcuts from untrusted sources.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.