CVE-2024-27819
LOWiPadOS < 17.5 - Unauthenticated Contacts Access from Lock Screen
Title source: llmDescription
The issue was addressed by restricting options offered on a locked device. This issue is fixed in iOS 17.5 and iPadOS 17.5. An attacker with physical access may be able to access contacts from the lock screen.
References (3)
Core 3
Core References
Vendor Advisory
https://support.apple.com/en-us/HT214101
Vendor Advisory
https://support.apple.com/kb/HT214101
Scores
CVSS v3
2.4
EPSS
0.0011
EPSS Percentile
29.5%
Attack Vector
PHYSICAL
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-284
Status
published
Products (3)
Apple/iOS and iPadOS
< 17.5
apple/ipados
< 17.5
apple/iphone_os
< 17.5
Published
Jun 10, 2024
Tracked Since
Feb 18, 2026