CVE-2024-23204 Apple's Shortcuts Vulnerability

Information has surfaced regarding a previously patched security vulnerability of high severity in Apple's Shortcuts app, which could enable a shortcut to access sensitive device data without user consent.

The security flaw, identified as CVE-2024-23204 with a CVSS score of 7.5, was addressed by Apple on January 22, 2024, through the release of iOS 17.3, iPadOS 17.3, macOS Sonoma 14.3, and watchOS 10.3.

Apple explained in an advisory that a shortcut might have been able to utilize sensitive data without user prompting, and this was rectified through the implementation of "additional permissions checks."

The Shortcuts app is a scripting tool that allows users to create customized workflows on iOS, iPadOS, macOS, and watchOS. It comes pre-installed on these operating systems.

Vulnerability Offers Serious Malicious Potential

Researchers highlighted the potential weaponization of the flaw to create a malicious shortcut capable of circumventing Transparency, Consent, and Control (TCC) policies. TCC is an Apple security framework designed to safeguard user data by requiring appropriate permissions.

The vulnerability is specifically linked to a shortcut action named "Expand URL," which can expand and clean up shortened URLs from services like t.co or bit.ly, while also removing UTM tracking parameters.

By leveraging this functionality, it became possible to transmit Base64-encoded data of a photo to a malicious website. This method involves selecting sensitive data (such as Photos, Contacts, Files, and clipboard data) within Shortcuts, importing it, converting it using the base64 encode option, and ultimately sending it to the malicious server.

The exfiltrated data is then captured and saved as an image on the attacker's end through a Flask application, opening the door for potential follow-on exploitation.

February 29, 2024
Loading...

Cyclonis Backup Details & Terms

The Free Basic Cyclonis Backup plan gives you 2 GB of cloud storage space with full functionality! No credit card required. Need more storage space? Purchase a larger Cyclonis Backup plan today! To learn more about our policies and pricing, see Terms of Service, Privacy Policy, Discount Terms and Purchase Page. If you wish to uninstall the app, please visit the Uninstallation Instructions page.

Cyclonis Password Manager Details & Terms

FREE Trial: 30-Day One-Time Offer! No credit card required for Free Trial. Full functionality for the length of the Free Trial. (Full functionality after Free Trial requires subscription purchase.) To learn more about our policies and pricing, see EULA, Privacy Policy, Discount Terms and Purchase Page. If you wish to uninstall the app, please visit the Uninstallation Instructions page.