Information Disclosure Vulnerability in Apple iOS and iPadOS
CVE-2024-44290

3.3LOW

Key Information:

Vendor
Apple
Vendor
CVE Published:
12 December 2024

Summary

An information disclosure vulnerability was identified in Apple's operating systems, allowing certain applications to ascertain the user's current location. This issue arises due to inadequate redaction of sensitive information. The vulnerability has been rectified in iOS 18.1, iPadOS 18.1, and watchOS 11.1, enhancing the protection of user privacy and safeguarding personal data from unauthorized access.

References

CVSS V3.1

Score:
3.3
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

.