vulnerability
OS X update for Shortcuts (CVE-2024-23245)
| Severity | CVSS | Published | Added | Modified |
|---|---|---|---|---|
| 2 | (AV:L/AC:M/Au:N/C:N/I:P/A:N) | Mar 8, 2024 | Mar 8, 2024 | Apr 6, 2026 |
Severity
2
CVSS
(AV:L/AC:M/Au:N/C:N/I:P/A:N)
Published
Mar 8, 2024
Added
Mar 8, 2024
Modified
Apr 6, 2026
Description
This issue was addressed by adding an additional prompt for user consent. This issue is fixed in macOS Monterey 12.7.4, macOS Sonoma 14.4, macOS Ventura 13.6.5. Third-party shortcuts may use a legacy action from Automator to send events to apps without user consent.
Solutions
apple-osx-upgrade-12_7_4apple-osx-upgrade-13_6_5apple-osx-upgrade-14_4
NEW
Explore Exposure Command
Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.