CVE-2024-40851

2.4LOW

Key Information

Vendor
Apple
Status
iOS And iPad OS
Vendor
CVE Published:
28 October 2024

Summary

This issue was addressed by restricting options offered on a locked device. This issue is fixed in iOS 18.1 and iPadOS 18.1. An attacker with physical access may be able to access contact photos from the lock screen.

Affected Version(s)

iOS and iPadOS < 18.1

CVSS V3.1

Score:
2.4
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Physical
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published.

Collectors

NVD DatabaseMitre Database
.