This issue was addressed by using HTTPS when sending information over the network. This issue is fixed in iOS 18.2 and iPadOS 18.2. A user in a privileged network position may be able to leak sensitive information.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

References
History

Fri, 28 Mar 2025 14:30:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple ipados
Apple iphone Os
CPEs cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*
Vendors & Products Apple
Apple ipados
Apple iphone Os

Fri, 21 Mar 2025 16:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-319
Metrics cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 17 Mar 2025 19:45:00 +0000

Type Values Removed Values Added
Description This issue was addressed by using HTTPS when sending information over the network. This issue is fixed in iOS 18.2 and iPadOS 18.2. A user in a privileged network position may be able to leak sensitive information.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2025-03-21T16:11:02.423Z

Reserved: 2024-08-20T21:45:40.789Z

Link: CVE-2024-44276

cve-icon Vulnrichment

Updated: 2025-03-21T16:10:33.010Z

cve-icon NVD

Status : Analyzed

Published: 2025-03-17T20:15:13.130

Modified: 2025-03-28T14:09:35.787

Link: CVE-2024-44276

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.