CVE-2024-23291: Apple iPadOS
Low severity, CVSS 3.3. EPSS: 0.6% chance of exploitation in the next 30 days.
A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4, tvOS 17.4, watchOS 10.4. A malicious app may be able to observe user data in log entries related to accessibility notifications.
Affected products
- Apple iPadOS: before 17.4 (fixed in 17.4)
- Apple iPhone OS: before 17.4 (fixed in 17.4)
- Apple macOS: from 14.0, before 14.4 (fixed in 14.4)
- Apple tvOS: before 17.4 (fixed in 17.4)
- Apple watchOS: before 10.4 (fixed in 10.4)
Published 2024-03-08. Last modified 2026-06-17.