CVE-2024-27835

LOW

iPadOS < 17.5 - Unauthenticated Notes Access from Lock Screen

Title source: llm
STIX 2.1

Description

This issue was addressed through improved state management. This issue is fixed in iOS 17.5 and iPadOS 17.5. An attacker with physical access to an iOS device may be able to access notes from the lock screen.

Scores

CVSS v3 2.4
EPSS 0.0014
EPSS Percentile 33.7%
Attack Vector PHYSICAL
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

CWE
CWE-287
Status published
Products (3)
Apple/iOS and iPadOS < 17.5
apple/ipados < 17.5
apple/iphone_os < 17.5
Published May 14, 2024
Tracked Since Feb 18, 2026