VYPR
Unrated severityNVD Advisory· Published Sep 16, 2024· Updated Apr 2, 2026

CVE-2024-40840

CVE-2024-40840

Description

An attacker with physical access to an unlocked device can use Siri to bypass lockscreen restrictions and access sensitive user data on iOS and iPadOS.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

An attacker with physical access to an unlocked device can use Siri to bypass lockscreen restrictions and access sensitive user data on iOS and iPadOS.

Vulnerability

CVE-2024-40840 is a vulnerability in iOS and iPadOS that allows Siri to access sensitive user data when the device is locked. The issue was addressed through improved state management. Affected versions include iOS and iPadOS prior to version 18, which is fixed in iOS 18 and iPadOS 18 [1]. The vulnerability is present on iPhone XS and later, iPad Pro 12.9-inch 3rd generation and later, iPad Pro 11-inch 1st generation and later, iPad Air 3rd generation and later, iPad 7th generation and later, and iPad mini 5th generation and later [1].

Exploitation

An attacker with physical access to the device can exploit this vulnerability by using Siri commands that bypass the lock screen. No authentication is required beyond having the device in a state where Siri is accessible from the lock screen [1]. The exact sequence of steps is not detailed in the available references, but the core requirement is physical possession of an unlocked or partially accessible device.

Impact

Successful exploitation allows the attacker to access sensitive user data through Siri, without needing to unlock the device. This could include personal information, messages, contacts, or other data that Siri can retrieve. The compromise occurs at the user's privilege level, as Siri operates within the user's session [1].

Mitigation

The vulnerability is fixed in iOS 18 and iPadOS 18, released on September 16, 2024 [1]. Users should update their devices to the latest OS version. No workarounds are listed in the available references [1].

AI Insight generated on May 24, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

3

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.