CVE-2024-23262

T

his issue was addressed with additional entitlement checks. This issue is fixed in visionOS 1.1, iOS 17.4 and iPadOS 17.4, iOS 16.7.6 and iPadOS 16.7.6. An app may be able to spoof system notifications and UI.

Configurations

Configuration 1 (hide)

OR cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:visionos:*:*:*:*:*:*:*:*

History

04 Nov 2025, 19:16

Type Values Removed Values Added
References
  • () https://support.apple.com/kb/HT214081 -
  • () https://support.apple.com/kb/HT214082 -
  • () https://support.apple.com/kb/HT214087 -

09 Dec 2024, 14:38

Type Values Removed Values Added
CVSS v2 : unknown
v3 : 4.3
v2 : unknown
v3 : 3.3
CPE cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:visionos:*:*:*:*:*:*:*:*
CWE NVD-CWE-noinfo
First Time Apple visionos
Apple iphone Os
Apple
Apple ipados
References () http://seclists.org/fulldisclosure/2024/Mar/26 - () http://seclists.org/fulldisclosure/2024/Mar/26 - Mailing List
References () https://support.apple.com/en-us/HT214081 - () https://support.apple.com/en-us/HT214081 - Vendor Advisory
References () https://support.apple.com/en-us/HT214082 - () https://support.apple.com/en-us/HT214082 - Vendor Advisory
References () https://support.apple.com/en-us/HT214087 - () https://support.apple.com/en-us/HT214087 - Vendor Advisory

21 Nov 2024, 15:15

Type Values Removed Values Added
References () http://seclists.org/fulldisclosure/2024/Mar/26 - () http://seclists.org/fulldisclosure/2024/Mar/26 -
References () https://support.apple.com/en-us/HT214081 - () https://support.apple.com/en-us/HT214081 -
References () https://support.apple.com/en-us/HT214082 - () https://support.apple.com/en-us/HT214082 -
References () https://support.apple.com/en-us/HT214087 - () https://support.apple.com/en-us/HT214087 -
CWE CWE-863
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 4.3

Information

Published : 2024-03-08 02:15

Updated : 2025-11-04 19:16


NVD link : CVE-2024-23262

Mitre link : CVE-2024-23262

CVE.ORG link : CVE-2024-23262


JSON object : View

Products Affected
CWE
NVD-CWE-noinfo CWE-863

Incorrect Authorization