vulnerability
OS X update for Shortcuts (CVE-2024-23245)
Severity | CVSS | Published | Added | Modified |
---|---|---|---|---|
2 | (AV:L/AC:M/Au:N/C:N/I:P/A:N) | Mar 8, 2024 | Mar 8, 2024 | Jan 28, 2025 |
Severity
2
CVSS
(AV:L/AC:M/Au:N/C:N/I:P/A:N)
Published
Mar 8, 2024
Added
Mar 8, 2024
Modified
Jan 28, 2025
Description
This issue was addressed by adding an additional prompt for user consent. This issue is fixed in macOS Sonoma 14.4, macOS Monterey 12.7.4, macOS Ventura 13.6.5. Third-party shortcuts may use a legacy action from Automator to send events to apps without user consent.
Solution(s)
apple-osx-upgrade-12_7_4apple-osx-upgrade-13_6_5apple-osx-upgrade-14_4

NEW
Explore Exposure Command
Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.