CVE-2024-54512

CRITICAL

iPadOS < 18.2 - Unauthorized User Fingerprinting via System Binary

Title source: llm
STIX 2.1

Description

The issue was addressed by removing the relevant flags. This issue is fixed in iOS 18.2 and iPadOS 18.2, watchOS 11.2. A system binary could be used to fingerprint a user's Apple Account.

References (2)

Core 2

Scores

CVSS v3 9.1
EPSS 0.0017
EPSS Percentile 37.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-863
Status published
Products (5)
Apple/iOS and iPadOS < 18.2
apple/ipados < 18.2
apple/iphone_os < 18.2
apple/watchos < 11.2
Apple/watchOS < 11.2
Published Jan 27, 2025
Tracked Since Feb 18, 2026