CVE-2024-40787 is a high-severity vulnerability affecting Apple's macOS, iOS, iPadOS, and watchOS that allows a shortcut to bypass Internet permission requirements. This local vulnerability (CVSS 7.1) could lead to high confidentiality and integrity impacts without user interaction, as it only requires local access and low privileges. While no public exploit code or active exploitation has been observed, Apple addressed this by implementing an additional user consent prompt in macOS Ventura 13.6.8, macOS Monterey 12.7.6, iOS 17.6, iPadOS 17.6, and watchOS 10.6.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 17.6CPE matchmatch criteria | cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:* | ||
< 17.6CPE matchmatch criteria | cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:* | ||
< 12.7.6CPE matchmatch criteria | cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:* | ||
>= 13.0, < 13.6.8CPE matchmatch criteria | cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:* | ||
>= 14.0, < 14.6CPE matchmatch criteria | cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.