CVE-2024-23291
Description
A malicious app could observe user data in log entries related to accessibility notifications due to insufficient redaction, fixed in Apple OS updates.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
A malicious app could observe user data in log entries related to accessibility notifications due to insufficient redaction, fixed in Apple OS updates.
A privacy issue in Apple operating systems allowed a malicious app to observe user data in log entries related to accessibility notifications. The root cause was that private data was not properly redacted from these log entries [1].
An attacker would need to have a malicious app installed on the device to exploit this vulnerability. No additional authentication or network access is required beyond the app's presence on the system. The vulnerability is present in log entries generated by accessibility notifications.
Successful exploitation could allow the malicious app to view sensitive user data that would otherwise be hidden. This includes information related to accessibility features, which may reveal personal details about the user.
Apple addressed this issue in iOS 17.4, iPadOS 17.4, macOS Sonoma 14.4, tvOS 17.4, and watchOS 10.4 by improving private data redaction for log entries [2].
AI Insight generated on May 20, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
8cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*range: <17.4
- (no CPE)range: =17.4
- Range: =14.4
- Range: =17.4
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
15- support.apple.com/en-us/HT214081nvdVendor Advisory
- support.apple.com/en-us/HT214084nvdVendor Advisory
- support.apple.com/en-us/HT214086nvdVendor Advisory
- support.apple.com/en-us/HT214088nvdVendor Advisory
- seclists.org/fulldisclosure/2024/Mar/21nvdMailing List
- seclists.org/fulldisclosure/2024/Mar/24nvdMailing List
- seclists.org/fulldisclosure/2024/Mar/25nvdMailing List
- support.apple.com/en-us/120881nvd
- support.apple.com/en-us/120882nvd
- support.apple.com/en-us/120893nvd
- support.apple.com/en-us/120895nvd
- support.apple.com/kb/HT214081nvd
- support.apple.com/kb/HT214084nvd
- support.apple.com/kb/HT214086nvd
- support.apple.com/kb/HT214088nvd
News mentions
0No linked articles in our index yet.