CVE-2024-40802 is a privilege escalation vulnerability affecting Apple macOS Sonoma, Monterey, and Ventura, allowing a local attacker to elevate their privileges due to insufficient checks. It carries a high CVSS score of 7.8, indicating a significant impact on confidentiality, integrity, and availability if exploited. While no public exploit code or active exploitation has been observed, and community discussion is minimal, affected systems should be updated to macOS Sonoma 14.6, macOS Monterey 12.7.6, or macOS Ventura 13.6.8 to mitigate the risk.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 12.0, < 12.7.6CPE matchmatch criteria | cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:* | ||
>= 13.0, < 13.6.8CPE matchmatch criteria | cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:* | ||
>= 14.0, < 14.6CPE matchmatch criteria | cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:* | ||
>= 0, < 12.7.6CPE match | cpe:2.3:a:apple:macos:*:*:*:*:*:*:*:* | ||
>= 0, < 13.6.8CPE match | cpe:2.3:a:apple:macos:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.