CVE-2024-23289: Apple iPadOS
Low severity, CVSS 3.3. EPSS: 0.3% chance of exploitation in the next 30 days.
A lock screen issue was addressed with improved state management. This issue is fixed in iOS 16.7.6 and iPadOS 16.7.6, iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4, watchOS 10.4. A person with physical access to a device may be able to use Siri to access private calendar information.
Affected products
- Apple iPadOS: before 16.7.6 (fixed in 16.7.6); from 17.0, before 17.4 (fixed in 17.4)
- Apple iPhone OS: before 16.7.6 (fixed in 16.7.6); from 17.0, before 17.4 (fixed in 17.4)
- Apple macOS: from 14.0, before 14.4 (fixed in 14.4)
- Apple watchOS: before 10.4 (fixed in 10.4)
Published 2024-03-08. Last modified 2026-06-17.