CVE-2024-40853: Apple iPadOS

Low severity, CVSS 3.3. EPSS: 0.2% chance of exploitation in the next 30 days.

This issue was addressed by restricting options offered on a locked device. This issue is fixed in iOS 18 and iPadOS 18. An attacker may be able to use Siri to enable Auto-Answer Calls.

Affected products

  • Apple iPadOS: before 18.0 (fixed in 18.0)
  • Apple iPhone OS: before 18.0 (fixed in 18.0)

Published 2024-10-28. Last modified 2026-06-17.