A timing side-channel issue was addressed with improvements to constant-time computation in cryptographic functions. This issue is fixed in macOS Sonoma 14.3, watchOS 10.3, tvOS 17.3, iOS 17.3 and iPadOS 17.3. An attacker may be able to decrypt legacy RSA PKCS#1 v1.5 ciphertexts without having the private key.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published: 2024-01-23T00:25:38.999Z

Updated: 2024-08-29T14:26:33.596Z

Reserved: 2024-01-12T22:22:21.477Z

Link: CVE-2024-23218

cve-icon Vulnrichment

Updated: 2024-08-01T22:59:32.071Z

cve-icon NVD

Status : Modified

Published: 2024-01-23T01:15:11.403

Modified: 2024-11-21T08:57:12.947

Link: CVE-2024-23218

cve-icon Redhat

No data.