CVE-2024-27821: Apple iPadOS
Medium severity, CVSS 4.7. EPSS: 0.9% chance of exploitation in the next 30 days.
A path handling issue was addressed with improved validation. This issue is fixed in iOS 17.5 and iPadOS 17.5, macOS Sonoma 14.5, watchOS 10.5. A shortcut may output sensitive user data without consent.
Affected products
- Apple iPadOS: before 17.5 (fixed in 17.5)
- Apple iPhone OS: before 17.5 (fixed in 17.5)
- Apple macOS: from 14.0, before 14.5 (fixed in 14.5)
- Apple watchOS: before 10.5 (fixed in 10.5)
Published 2024-05-14. Last modified 2026-06-17.