CVE-2024-54485

LOW

iPadOS < 17.7.3 and < 18.2 - Unauthenticated Sensitive Information Exposure via Lock Screen Notifications

Title source: llm
STIX 2.1

Description

The issue was addressed by adding additional logic. This issue is fixed in iOS 18.2 and iPadOS 18.2, iPadOS 17.7.3, macOS Sequoia 15.2. An attacker with physical access to an iOS device may be able to view notification content from the lock screen.

Scores

CVSS v3 2.4
EPSS 0.0028
EPSS Percentile 19.5%
Attack Vector PHYSICAL
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-922
Status published
Products (5)
Apple/iOS and iPadOS < 18.2
apple/ipados < 17.7.3
Apple/iPadOS < 17.7.3
apple/iphone_os < 18.2
Apple/macOS < 15.2
Published Dec 12, 2024
Tracked Since Feb 18, 2026