This issue was addressed by restricting options offered on a locked device. This issue is fixed in iOS 18 and iPadOS 18. An attacker may be able to see recent photos without authentication in Assistive Access.
Advisories
Source ID Title
EUVD EUVD EUVD-2024-38688 This issue was addressed by restricting options offered on a locked device. This issue is fixed in iOS 18 and iPadOS 18. An attacker may be able to see recent photos without authentication in Assistive Access.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Wed, 05 Nov 2025 02:30:00 +0900

Type Values Removed Values Added
References

Sun, 13 Jul 2025 22:45:00 +0900

Type Values Removed Values Added
Metrics epss

{'score': 0.00108}

epss

{'score': 0.0012}


Thu, 20 Mar 2025 03:15:00 +0900

Type Values Removed Values Added
Weaknesses CWE-862

Fri, 13 Dec 2024 00:45:00 +0900

Type Values Removed Values Added
First Time appeared Apple ipados
Apple iphone Os
Weaknesses NVD-CWE-noinfo
CPEs cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*
Vendors & Products Apple ipados
Apple iphone Os

Tue, 17 Sep 2024 23:30:00 +0900

Type Values Removed Values Added
First Time appeared Apple
Apple ios And Ipados
CPEs cpe:2.3:o:apple:ios_and_ipados:*:*:*:*:*:*:*:*
Vendors & Products Apple
Apple ios And Ipados
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 17 Sep 2024 08:30:00 +0900

Type Values Removed Values Added
Description This issue was addressed by restricting options offered on a locked device. This issue is fixed in iOS 18 and iPadOS 18. An attacker may be able to see recent photos without authentication in Assistive Access.
References

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2025-11-04T16:13:24.473Z

Reserved: 2024-07-10T17:11:04.710Z

Link: CVE-2024-40852

cve-icon Vulnrichment

Updated: 2024-09-17T13:24:31.486Z

cve-icon NVD

Status : Modified

Published: 2024-09-17T00:15:49.440

Modified: 2025-11-04T17:16:01.280

Link: CVE-2024-40852

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses