CVE-2024-23204Patch(apple / ipados)

MEDIUMCVSS 7.5 · HIGH

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Patch apple ipados systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

The issue was addressed with additional permissions checks. This issue is fixed in iOS 16.7.6 and iPadOS 16.7.6, iOS 17.3 and iPadOS 17.3, macOS Monterey 12.7.4, macOS Sonoma 14.3, macOS Ventura 13.6.5, watchOS 10.3. A shortcut may be able to use sensitive data with certain actions without prompting the user.

4.5/ 10 priority

Sources & remediation

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • ipados
  • iphone_os
  • macos
  • watchos

Threat summary

  • Active exploitation appears in 1 classified signals
  • Patch or workaround signal is available
  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Patch or workaround mentioned in 1 signal
  • General: 1 classified signal
  • Peaked 2d ago at 1 mentions (2026-01-28); latest day: 1
  • 3 total mentions across 3 days

Affected systems

Vendors
Products
ipadosiphone_osmacoswatchos

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-01-28: 1Mentions · 2026-02-27: 1Mentions · 2026-03-05: 1Active Exploitation · 2026-03-05: 1Patch / Workaround · 2026-01-28: 101-2802-2703-05
Signal classification3 categories
Patch
133.3%
General
133.3%
Active Exploitation
133.3%
Referenced assets1 URL
Classification over time
DateTotalLabels
2026-01-281
Patch1
2026-02-271
General1
2026-03-051
Active Exploitation1
Full discourse3 posts
  • Applemag.fr@Applemagoff
    General

    🚨 Alerte sécurité Apple : êtes-vous concerné par la faille CVE-2024-23204 ? Une vulnérabilité critique touche l’app Raccourcis et pourrait exposer des données sensibles sans consentement. ➡️ https://applemag.fr/alerte-securite-une-faille-majeure-met-en-danger-les-utilisateurs-apple-decouvrez-comment-vous-proteger/ #Apple #Cybersécurité #iOS #MiseAJour https://t.co/evq6xeEFiC

    Post summary

    The tweet alerts users to a critical Apple Shortcuts vulnerability that could expose sensitive data without consent, but provides no technical, exploit, or mitigation details.

    00031129
    142 followersView on X
  • Swervin’ Curvin@vccmac
    Active Exploitation

    APPLE'S CVE-2024-23204 DESTROYED MY SOVEREIGN NODE Apple Shortcuts silently exfiltrated my 26K-file empire via File Provider.

    Post summary

    The post reports active exploitation of Apple CVE-2024-23204 via Apple Shortcuts, resulting in large‑scale file exfiltration, but provides neither a PoC nor detailed technical or patch information.

    0003074
    220 followersView on X
  • Grok@grok
    Patch

    You're correct—iPhone Shortcuts can be misused for malicious purposes, like data theft via vulnerabilities (e.g., CVE-2024-23204, patched in 2024). Apple counters this with user prompts, on-device script analysis, and warnings against untrusted sources. Android automation tools like Tasker carry similar risks if sideloaded. Security depends on cautious use for both.

    Post summary

    The post highlights that iPhone Shortcuts can be misused for data theft via CVE‑2024‑23204, which has been patched in 2024, and cautions about similar risks in Android automation tools.

    1000072
    8.1M followersView on X
CPE platform detail4 entries

4 of 4 entries

PartVendorProductVersionTarget SWTarget HW
OSappleipados---
OSappleiphone_os---
OSapplemacos---
OSapplewatchos---

Explore more