CVE-2024-54470

MEDIUM

iPadOS < 17.7.1 and < 18.1 - Unauthenticated Contacts Access from Lock Screen

Title source: llm
STIX 2.1

Description

A logic issue was addressed with improved checks. This issue is fixed in iOS 17.7.1 and iPadOS 17.7.1, iOS 18.1 and iPadOS 18.1. An attacker with physical access may be able to access contacts from the lock screen.

References (2)

Core 2
Core References
Release Notes, Vendor Advisory
https://support.apple.com/en-us/121563
Release Notes, Vendor Advisory
https://support.apple.com/en-us/121567

Scores

CVSS v3 4.6
EPSS 0.0013
EPSS Percentile 32.1%
Attack Vector PHYSICAL
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-862
Status published
Products (6)
Apple/iOS and iPadOS < 17.7.1
Apple/iOS and iPadOS < 18.1
apple/ipados 18.0
apple/ipados < 17.7.1
apple/iphone_os 18.0
apple/iphone_os < 17.7.1
Published Jan 15, 2025
Tracked Since Feb 18, 2026