CVE-2024-40862

MEDIUM

Xcode < 16.0 - Unauthorized Apple ID Exposure

Title source: llm
STIX 2.1

Description

A privacy issue was addressed by removing sensitive data. This issue is fixed in Xcode 16. An attacker may be able to determine the Apple ID of the owner of the computer.

References (2)

Core 2

Scores

CVSS v3 5.3
EPSS 0.0017
EPSS Percentile 37.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-200
Status published
Products (2)
Apple/Xcode < 16
apple/xcode < 16.0
Published Sep 17, 2024
Tracked Since Feb 18, 2026