This issue was addressed through improved state management. This issue is fixed in iOS 17.6 and iPadOS 17.6, iOS 16.7.9 and iPadOS 16.7.9, macOS Ventura 13.6.8. An attacker may be able to view sensitive user information.
CVE ID: CVE-2024-40786
CVSS Base Severity: HIGH
CVSS Base Score: 7.5
Vendor: Apple, Apple, Apple
Product: iOS and iPadOS, iOS and iPadOS, macOS
EPSS Score: 0.23% (probability of being exploited)
EPSS Percentile: 45.5% (scored less or equal to compared to others)
EPSS Date: 2025-04-17 (when was this score calculated)
SSVC Exploitation: none
SSVC Technical Impact: partial
SSVC Automatable: false