CVE-2024-23240: Apple Ipad OS

Low severity, CVSS 2.4. EPSS: 0.3% chance of exploitation in the next 30 days.

The issue was addressed with improved checks. This issue is fixed in iOS 17.4 and iPadOS 17.4. Shake-to-undo may allow a deleted photo to be re-surfaced without authentication.

Affected products

  • Apple Ipad OS: before 17.4 (fixed in 17.4)
  • Apple iPhone OS: before 17.4 (fixed in 17.4)

Published 2024-03-08. Last modified 2026-06-17.