Logitech Options+ Vulnerability Allows Local Attacker to Abuse Camera Permissions
CVE-2024-8011

5.5MEDIUM

Key Information:

Vendor

Logitech

Status
Vendor
CVE Published:
25 August 2024

What is CVE-2024-8011?

Logitech Options+ on MacOS versions preceding 1.72 is susceptible to a local library injection flaw. This vulnerability enables a malicious local actor to inject a dynamic library into the Options+ runtime. The injected library can exploit permissions granted by the user, potentially allowing unauthorized access and manipulation of sensitive features, such as the Camera. Proper security measures and updates are recommended to mitigate the risks associated with this vulnerability.

Affected Version(s)

Options+ MacOS 0 <= 1.70.551909

Options+ MacOS 1.72.564177

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

ferdogan
.