CVE-2024-44191

MEDIUM

Xcode < 16 - Unauthorized Bluetooth Access via State Management Issue

Title source: llm
STIX 2.1

Description

This issue was addressed through improved state management. This issue is fixed in Xcode 16, iOS 17.7 and iPadOS 17.7, iOS 18 and iPadOS 18, macOS Sequoia 15, tvOS 18, visionOS 2, watchOS 11. An app may gain unauthorized access to Bluetooth.

References (11)

Core 11

Scores

CVSS v3 5.5
EPSS 0.0004
EPSS Percentile 11.5%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

Status published
Products (14)
Apple/iOS and iPadOS < 17.7
Apple/iOS and iPadOS < 18
apple/ipados < 17.7
apple/iphone_os < 17.7
Apple/macOS < 15
apple/macos < 15.0
Apple/tvOS < 18
apple/tvos < 18.0
Apple/visionOS < 2
apple/visionos < 2.0
... and 4 more
Published Sep 17, 2024
Tracked Since Feb 18, 2026