Access Issue in Shortcuts for iOS by Apple
CVE-2019-7290

10CRITICAL

Key Information:

Vendor
Apple
Status
Vendor
CVE Published:
18 December 2019

Summary

An access issue in Apple's Shortcuts, identified in versions prior to 2.1.3 for iOS, may lead to an unauthorized circumvention of the sandbox restrictions. This inability to effectively restrict access allows a sandboxed process to potentially exploit vulnerabilities, impacting the overall security integrity of the iOS environment. Apple has addressed this concern with additional sandbox restrictions in the latest update.

Affected Version(s)

Shortcuts < unspecified

References

CVSS V3.1

Score:
10
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.