This issue was addressed by adding an additional prompt for user consent. This issue is fixed in macOS Sonoma 14.4, macOS Monterey 12.7.4, macOS Ventura 13.6.5. Third-party shortcuts may use a legacy action from Automator to send events to apps without user consent.
Metrics
Affected Vendors & Products
References
History
Fri, 06 Dec 2024 02:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Apple
Apple macos |
|
Weaknesses | NVD-CWE-noinfo | |
CPEs | cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:* | |
Vendors & Products |
Apple
Apple macos |
Mon, 04 Nov 2024 21:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
cvssV3_1
|
MITRE
Status: PUBLISHED
Assigner: apple
Published: 2024-03-08T01:36:01.619Z
Updated: 2024-11-04T21:07:32.363Z
Reserved: 2024-01-12T22:22:21.483Z
Link: CVE-2024-23245
Vulnrichment
Updated: 2024-08-01T22:59:32.088Z
NVD
Status : Analyzed
Published: 2024-03-08T02:15:48.287
Modified: 2024-12-06T02:08:18.640
Link: CVE-2024-23245
Redhat
No data.