CVE-2024-54492General(apple / ipados)

LOWCVSS 5.9 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

This issue was addressed by using HTTPS when sending information over the network. This issue is fixed in iOS 18.2 and iPadOS 18.2, iPadOS 17.7.3, macOS Sequoia 15.2, visionOS 2.2. An attacker in a privileged network position may be able to alter network traffic.

0.5/ 10 priority

Sources & remediation

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • ipados
  • iphone_os
  • macos
  • visionos

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • General: 1 classified signal
  • 1 total mentions across 1 day

Affected systems

Vendors
Products
ipadosiphone_osmacosvisionos

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-03-27: 103-27
Signal classification1 categories
General
1100.0%
Full discourse1 post
  • Mysk 🇨🇦🇩🇪@mysk_co
    General

    Good to know but every vulnerability we discovered and reported to Apple also affected the Lockdown Mode. This includes CVE-2024-54492 that impacted the Passwords app. An option to "Allow Contacting Websites" was added starting iOS 26 https://t.co/Se72KykINe

    Post summary

    The tweet confirms CVE‑2024‑54492 impacted Apple’s Passwords app and Lockdown Mode and notes that iOS 26 added an option to allow contacting websites, but it offers no technical details, PoC, or evidence of active exploitation.

    150542614.0K
    16.7K followersView on X
CPE platform detail4 entries

4 of 4 entries

PartVendorProductVersionTarget SWTarget HW
OSappleipados---
OSappleiphone_os---
OSapplemacos---
OSapplevisionos---

Explore more