VYPR
Low severity3.3NVD Advisory· Published Apr 24, 2024· Updated Apr 2, 2026

CVE-2024-23228

CVE-2024-23228

Description

CVE-2024-23228: Locked Notes content in iOS 17.3 and iPadOS 17.3 could be unexpectedly unlocked due to a state management issue.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

CVE-2024-23228: Locked Notes content in iOS 17.3 and iPadOS 17.3 could be unexpectedly unlocked due to a state management issue.

Vulnerability

Description

CVE-2024-23228 is a security issue in the Notes app on iOS and iPadOS, where locked notes could be unexpectedly unlocked. Apple addressed the issue through improved state management in iOS 17.3 and iPadOS 17.3 [1][2]. The root cause appears to be a flaw in how the operating system handles the lock state of notes, potentially allowing a bypass of the intended encryption or access controls on locked content.

Exploitation and

Impact

The vulnerability has a CVSS v3 base score of 3.3, indicating a low severity. The attack vector is local, requiring physical access to an unlocked device or the ability to trigger the lock state failure under specific conditions. No authentication is needed beyond the device being in an unlocked state. An attacker could view the content of notes that the user intended to keep locked, leading to a loss of confidentiality of sensitive information stored in Notes [2].

Mitigation

Apple released the fix for this vulnerability in iOS 17.3 and iPadOS 17.3 on January 22, 2024 [1]. Users are advised to update their devices to the latest operating system version to protect against this issue. There is no indication of this vulnerability being exploited in the wild, and no workaround is available aside from updating.

AI Insight generated on May 20, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

4
  • Apple Inc./Ipados2 versions
    cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*range: <17.3
    • (no CPE)range: <17.3
  • cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*
    Range: <17.3
  • Apple Inc./iOSllm-fuzzy
    Range: <17.3

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

3

News mentions

0

No linked articles in our index yet.