CVE-2023-40529: Apple iPadOS

Low severity, CVSS 2.4. EPSS: 0.2% chance of exploitation in the next 30 days.

This issue was addressed with improved redaction of sensitive information. This issue is fixed in iOS 17 and iPadOS 17. A person with physical access to a device may be able to use VoiceOver to access private calendar information.

Affected products

  • Apple iPadOS: before 17.0 (fixed in 17.0)
  • Apple iPhone OS: before 17.0 (fixed in 17.0)

Published 2024-01-10. Last modified 2026-06-17.