Entreprise d'experts en Sécurité Informatique : Audits et conseils en cybersécurité
Entreprise française de cybersécurité depuis 2004
☎ 03 60 47 09 81 - info@securiteinfo.com


CVE-2024-40787

Description

This issue was addressed by adding an additional prompt for user consent. This issue is fixed in macOS Ventura 13.6.8, macOS Monterey 12.7.6, iOS 17.6 and iPadOS 17.6, watchOS 10.6, macOS Sonoma 14.6. A shortcut may be able to bypass Internet permission requirements.

POC

Reference

- http://seclists.org/fulldisclosure/2024/Jul/16

- http://seclists.org/fulldisclosure/2024/Jul/18

- http://seclists.org/fulldisclosure/2024/Jul/19

Github

No PoCs found on GitHub currently.