This issue was addressed with additional entitlement checks. This issue is fixed in macOS Sonoma 14.5, macOS Ventura 13.6.7, macOS Monterey 12.7.5, iOS 16.7.8 and iPadOS 16.7.8. An unprivileged app may be able to log keystrokes in other apps including those using secure input mode.
CVE ID: CVE-2024-27799
Vendor: Apple
Product: iOS and iPadOS
EPSS Score: 0.05% (probability of being exploited)
EPSS Percentile: 24.62% (scored less or equal to compared to others)
EPSS Date: 2025-03-14 (when was this score calculated)