Medium severity5.5NVD Advisory· Published Jul 29, 2024· Updated Apr 2, 2026
CVE-2024-40836
CVE-2024-40836
Description
A logic issue was addressed with improved checks. This issue is fixed in iOS 16.7.9 and iPadOS 16.7.9, iOS 17.6 and iPadOS 17.6, macOS Sonoma 14.6, watchOS 10.6. A shortcut may be able to use sensitive data with certain actions without prompting the user.
Affected products
4Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
16- support.apple.com/en-us/HT214116nvdVendor Advisory
- support.apple.com/en-us/HT214117nvdVendor Advisory
- support.apple.com/en-us/HT214119nvdVendor Advisory
- support.apple.com/en-us/HT214124nvdVendor Advisory
- seclists.org/fulldisclosure/2024/Jul/16nvdMailing List
- seclists.org/fulldisclosure/2024/Jul/17nvdMailing List
- seclists.org/fulldisclosure/2024/Jul/18nvdMailing List
- seclists.org/fulldisclosure/2024/Jul/21nvdMailing List
- support.apple.com/en-us/120908nvd
- support.apple.com/en-us/120909nvd
- support.apple.com/en-us/120911nvd
- support.apple.com/en-us/120916nvd
- support.apple.com/kb/HT214116nvd
- support.apple.com/kb/HT214117nvd
- support.apple.com/kb/HT214119nvd
- support.apple.com/kb/HT214124nvd
News mentions
0No linked articles in our index yet.