CVE-2024-23295: Apple visionOS

Medium severity, CVSS 5.5. EPSS: 0.3% chance of exploitation in the next 30 days.

A permissions issue was addressed to help ensure Personas are always protected. This issue is fixed in visionOS 1.1. An unauthenticated user may be able to use an unprotected Persona.

Affected products

  • Apple visionOS: before 1.1 (fixed in 1.1)

Published 2024-03-08. Last modified 2026-06-17.