CVE-2024-23243 is a privacy vulnerability affecting Apple iOS and iPadOS versions prior to 17.4, where an application could read sensitive location information due to insufficient redaction of private data in log entries. This vulnerability has a low CVSS score of 3.3, indicating a low impact on confidentiality and requiring user interaction for exploitation. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion, with only one article mentioning it.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 17.4CPE matchmatch criteria | cpe:2.3:o:apple:ipad_os:*:*:*:*:*:*:*:* | ||
< 17.4CPE matchmatch criteria | cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.0 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.