CVE-2024-23291: Apple iPadOS

Low severity, CVSS 3.3. EPSS: 0.6% chance of exploitation in the next 30 days.

A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4, tvOS 17.4, watchOS 10.4. A malicious app may be able to observe user data in log entries related to accessibility notifications.

Affected products

  • Apple iPadOS: before 17.4 (fixed in 17.4)
  • Apple iPhone OS: before 17.4 (fixed in 17.4)
  • Apple macOS: from 14.0, before 14.4 (fixed in 14.4)
  • Apple tvOS: before 17.4 (fixed in 17.4)
  • Apple watchOS: before 10.4 (fixed in 10.4)

Published 2024-03-08. Last modified 2026-06-17.