This issue was addressed by restricting options offered on a locked device. This issue is fixed in watchOS 9.5. An attacker with physical access to a locked Apple Watch may be able to view user photos or contacts via accessibility features.
CVSS Details
- CVSS 3.1 Base Score: 2.4
- CVSS 3.1 Vector: (CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Apple Osx Accessibility | — | — | Oct 14, 2024 | Jun 23, 2023 |
| Apple Osx Accounts | — | — | Oct 14, 2024 | Jun 23, 2023 |
| Apple Osx Amd | — | — | Oct 14, 2024 | Jun 23, 2023 |
| Apple Osx Applemobilefileintegrity | — | — | Oct 14, 2024 | Jun 23, 2023 |
| Apple Osx Associateddomains | — | — | Oct 14, 2024 | Jun 23, 2023 |
| Apple Osx Contacts | — | — | Oct 14, 2024 | Jun 23, 2023 |
| Apple Osx Corelocation | — | — | Oct 14, 2024 | Jun 23, 2023 |
| Apple Osx Coreservices | — | — | Oct 14, 2024 | Jun 23, 2023 |
| Apple Osx Cups | — | — | Oct 14, 2024 | Jun 23, 2023 |
| Apple Osx Dcerpc | — | — | Oct 14, 2024 | Jun 23, 2023 |
| Apple Osx Desktopservices | — | — | Oct 14, 2024 | Jun 23, 2023 |
| Apple Osx Facegallery | — | Upgrade macOS to the latest version | Sep 6, 2023 | Jun 23, 2023 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub