- Description
- A path handling issue was addressed with improved validation. This issue is fixed in iOS 17.5 and iPadOS 17.5, watchOS 10.5, macOS Sonoma 14.5. A shortcut may output sensitive user data without consent.
- Source
- product-security@apple.com
- NVD status
- Analyzed
CVSS 3.1
- Type
- Primary
- Base score
- 4.7
- Impact score
- 3.6
- Exploitability score
- 1
- Vector string
- CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N
- Severity
- MEDIUM
- Hype score
- Not currently trending
آسیب پذیری از نوع race condition برای اپلیکیشن WorkflowKit منتشر شده است که به یک اپلیکیشن مخرب اجازه بازرسی و intercept و تغییر در shortcut های سیستم macOS را می دهد. کد شناسایی این آسیب پذیری CVE-2024-27821 می باشد. https://t.co/Poz3aKY03t https://t.co/JaNPb0pAGo
@AmirHossein_sec
2 Dec 2024
41 Impressions
0 Retweets
1 Like
0 Bookmarks
0 Replies
0 Quotes
Apple macOS - WorkflowKit の脆弱性 CVE-2024-27821 が FIX:PoC も公開 https://t.co/0Kz7B424cz #Apple #Exploit #macOS #PoCExploit #Vulnerability #WorkflowKit
@iototsecnews
2 Dec 2024
149 Impressions
1 Retweet
0 Likes
0 Bookmarks
0 Replies
0 Quotes
https://t.co/lvjiYWCSV6 I'm excited to announce a writeup for CVE-2024-27821, a fun WorkflowKit bug I discovered back in March of this year! I've also supplied PoCs, one for generation and one for signing.
@0xilis
17 Nov 2024
264 Impressions
2 Retweets
5 Likes
0 Bookmarks
0 Replies
1 Quote
[
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "E7F2E11C-4A7D-4E71-BFAA-396B0549F649",
"versionEndExcluding": "17.5"
},
{
"criteria": "cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "E9C4B45E-AF58-4D7C-B73A-618B06AED56E",
"versionEndExcluding": "17.5"
},
{
"criteria": "cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "6AB18623-7D06-4946-99FC-808A4A913ED9",
"versionEndExcluding": "14.5",
"versionStartIncluding": "14.0"
},
{
"criteria": "cpe:2.3:o:apple:watchos:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "CC4B1E01-BE73-48F8-9BD5-32F7C57EB45A",
"versionEndExcluding": "10.5"
}
],
"operator": "OR"
}
]
}
]