Apple devices: Internet permission bypass via shortcut (CVE-2024-40787) #shorts #breaking
CVE
This CVE, identified as CVE-2024-40787, reveals a vulnerability where a shortcut can bypass Internet permission requirements on Apple devices. This issue affects iOS, iPadOS, macOS, and watchOS, and was first discovered 0 months ago. Although it is not an 0-day vulnerability, it is significant because it allows potential attackers to gain unauthorized Internet access without user consent. The primary concern is that this vulnerability could be exploited on any Apple device, putting all users at risk. The issue has been addressed by requiring an additional prompt for user consent.
Watch the full video on YouTube: CVE-2024-40787
Remediation and exploitation details
This chain involves the following actors
This following systems are involved
Attack entry point
Remediation actions
Exploitation actions
Related Content
NOTE: The following related content has not been vetted and may be unsafe.
- https://support.apple.com/en-us/HT214117
- https://support.apple.com/en-us/HT214120
- https://support.apple.com/en-us/HT214124
- https://support.apple.com/en-us/HT214119
- https://support.apple.com/en-us/HT214118
- http://seclists.org/fulldisclosure/2024/Jul/16
- http://seclists.org/fulldisclosure/2024/Jul/21
- http://seclists.org/fulldisclosure/2024/Jul/20
- http://seclists.org/fulldisclosure/2024/Jul/18
- http://seclists.org/fulldisclosure/2024/Jul/19