advisory 55

Advisory 55: CVE-2024-23204 – Apple iOS and macOS vulnerability

Release Date: 23rd of February 2024

Impact : HIGH / CRITICAL

TLP Rating: Clear

CERT Vanuatu (CERTVU) and the Office of the Chief Information Officer (OGCIO) provide the following advisory.

What is it?

The Apple iOS and macOS vulnerability known as CVE-2024-23204 enables the creation of a malicious shortcut file capable of bypassing Apple’s Transparency, Consent, and Control (TCC) security framework. This framework is designed to ensure that apps explicitly ask users for permission before accessing certain data or functionalities.

References