CVE-2024-23295

MEDIUM

visionOS < 1.1 - Unauthenticated Unprotected Persona Access

Title source: llm
STIX 2.1

Description

A permissions issue was addressed to help ensure Personas are always protected. This issue is fixed in visionOS 1.1. An unauthenticated user may be able to use an unprotected Persona.

Scores

CVSS v3 5.5
EPSS 0.0008
EPSS Percentile 23.3%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-276
Status published
Products (2)
apple/visionos < 1.1
Apple/visionOS < 1.1
Published Mar 08, 2024
Tracked Since Feb 18, 2026