CVE-2024-40836: Apple iPadOS
Medium severity, CVSS 5.5. EPSS: 0.6% chance of exploitation in the next 30 days.
A logic issue was addressed with improved checks. This issue is fixed in iOS 16.7.9 and iPadOS 16.7.9, iOS 17.6 and iPadOS 17.6, macOS Sonoma 14.6, watchOS 10.6. A shortcut may be able to use sensitive data with certain actions without prompting the user.
Affected products
- Apple iPadOS: before 16.7.9 (fixed in 16.7.9); from 17.0, before 17.6 (fixed in 17.6)
- Apple iPhone OS: before 16.7.9 (fixed in 16.7.9); from 17.0, before 17.6 (fixed in 17.6)
- Apple macOS: from 14.0, before 14.6 (fixed in 14.6)
- Apple watchOS: before 10.6 (fixed in 10.6)
Published 2024-07-29. Last modified 2026-06-17.