CVE-2024-23289: Apple iPadOS

Low severity, CVSS 3.3. EPSS: 0.3% chance of exploitation in the next 30 days.

A lock screen issue was addressed with improved state management. This issue is fixed in iOS 16.7.6 and iPadOS 16.7.6, iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4, watchOS 10.4. A person with physical access to a device may be able to use Siri to access private calendar information.

Affected products

  • Apple iPadOS: before 16.7.6 (fixed in 16.7.6); from 17.0, before 17.4 (fixed in 17.4)
  • Apple iPhone OS: before 16.7.6 (fixed in 16.7.6); from 17.0, before 17.4 (fixed in 17.4)
  • Apple macOS: from 14.0, before 14.4 (fixed in 14.4)
  • Apple watchOS: before 10.4 (fixed in 10.4)

Published 2024-03-08. Last modified 2026-06-17.