CVE-2024-44171

MEDIUM

iPadOS < 17.7 - Unauthenticated Control of Nearby Devices via Accessibility Features

Title source: llm
STIX 2.1

Description

This issue was addressed through improved state management. This issue is fixed in iOS 17.7 and iPadOS 17.7, iOS 18 and iPadOS 18, watchOS 11. An attacker with physical access to a locked device may be able to Control Nearby Devices via accessibility features.

References (6)

Core 6

Scores

CVSS v3 4.6
EPSS 0.0008
EPSS Percentile 23.7%
Attack Vector PHYSICAL
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

Status published
Products (6)
Apple/iOS and iPadOS < 17.7
Apple/iOS and iPadOS < 18
apple/ipados < 17.7
apple/iphone_os < 17.7
Apple/watchOS < 11
apple/watchos < 11.0
Published Sep 17, 2024
Tracked Since Feb 18, 2026