CVE-2024-40822: Apple iPadOS

Low severity, CVSS 2.4. EPSS: 0.4% chance of exploitation in the next 30 days.

This issue was addressed by restricting options offered on a locked device. This issue is fixed in iOS 16.7.9 and iPadOS 16.7.9, iOS 17.6 and iPadOS 17.6, macOS Sonoma 14.6, watchOS 10.6. An attacker with physical access to a device may be able to access contacts from the lock screen.

Affected products

  • Apple iPadOS: before 16.7.9 (fixed in 16.7.9); from 17.0, before 17.6 (fixed in 17.6)
  • Apple iPhone OS: before 16.7.9 (fixed in 16.7.9); from 17.0, before 17.6 (fixed in 17.6)
  • Apple macOS: before 14.6 (fixed in 14.6)
  • Apple watchOS: before 10.6 (fixed in 10.6)

Published 2024-07-29. Last modified 2026-06-17.