CVE-2024-44123
Description
A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 18 and iPadOS 18, macOS Sequoia 15. A malicious app with root privileges may be able to access keyboard input and location information without user consent.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
A local attacker with root privileges on Apple devices can access keyboard input and location data without user consent, fixed in iOS 18, iPadOS 18, and macOS Sequoia 15.
Root
Cause
CVE-2024-44123 is a permissions issue in Apple's operating systems that allows a malicious application with root privileges to access sensitive user data, specifically keyboard input and location information, without obtaining user consent. The vulnerability stems from inadequate restrictions on privileged processes, enabling them to bypass standard user authorization checks [1][2].
Exploitation
Prerequisites
To exploit this vulnerability, an attacker must already have root-level access on the target device, meaning they have compromised the system at the highest privilege level. No user interaction is required beyond the initial compromise, as the malicious app can silently monitor keyboard input and location services. The attack vector is local, requiring the app to be installed on the device [1][2].
Impact
An attacker with root privileges can exfiltrate sensitive user information, such as keystrokes (potentially capturing passwords, messages, and other typed data) and real-time location data. This could lead to privacy breaches, identity theft, or physical tracking [1][2].
Mitigation
Apple addressed the issue in iOS 18, iPadOS 18, and macOS Sequoia 15 by implementing improved checks on privileged app permissions. Users are strongly advised to update their devices to the latest available versions to block this attack. No workarounds have been provided, and the vulnerability is not known to be exploited in the wild at the time of disclosure [1][2].
AI Insight generated on May 20, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
6cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*range: <18.0
- (no CPE)range: <18
- Range: <15
- Range: <18
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- support.apple.com/en-us/121238nvdRelease NotesVendor Advisory
- support.apple.com/en-us/121250nvdRelease NotesVendor Advisory
News mentions
0No linked articles in our index yet.