VYPR
Unrated severityNVD Advisory· Published Sep 16, 2024· Updated Apr 2, 2026

CVE-2024-44171

CVE-2024-44171

Description

An attacker with physical access to a locked device may control nearby devices via accessibility features, fixed in iOS 17.7/18, iPadOS 17.7/18, and watchOS 11.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

An attacker with physical access to a locked device may control nearby devices via accessibility features, fixed in iOS 17.7/18, iPadOS 17.7/18, and watchOS 11.

Vulnerability

A state management flaw in accessibility features on Apple devices allowed an attacker with physical access to a locked device to control nearby devices. Affected versions include iOS and iPadOS prior to 17.7 and 18, and watchOS prior to 11. The issue was addressed through improved state management. [1][2][3]

Exploitation

An attacker must have physical access to a locked device. By leveraging accessibility features, the attacker could interact with the device to send commands to nearby devices without unlocking the device. No authentication is bypassed on the attacker's device, but the locked state's restrictions are circumvented for controlling nearby devices. [1][2][3]

Impact

A successful exploit allows the attacker to control nearby devices, which may lead to disclosure or manipulation of information on those devices, depending on the attacker's actions and the capabilities of the accessibility features used. The attacker does not gain code execution or escalate privileges on the locked device itself. [1][2][3]

Mitigation

Apple released fixes in iOS 17.7 and iPadOS 17.7 on September 16, 2024, and in iOS 18, iPadOS 18, and watchOS 11 on the same date. Users should update their devices to the latest available versions as soon as possible. No workarounds have been disclosed. [1][2][3]

AI Insight generated on May 24, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

5

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

3

News mentions

0

No linked articles in our index yet.