ZeroSecurity - Information Security News
  • Home
  • Security
    • Exploits
    • Mobile Security
  • Malware
  • Breaches
  • Crypto
  • Privacy
  • Tech
    • AI
    • Downloads
      • Malwarebytes
      • Exploits
      • Paper Downloads
    • Reviews
No Result
View All Result
SUBSCRIBE
ZeroSecurity - Information Security News
  • Home
  • Security
    • Exploits
    • Mobile Security
  • Malware
  • Breaches
  • Crypto
  • Privacy
  • Tech
    • AI
    • Downloads
      • Malwarebytes
      • Exploits
      • Paper Downloads
    • Reviews
No Result
View All Result
ZeroSecurity - Information Security News
No Result
View All Result
Home Mobile Security

Bitdefender Discovers Critical Vulnerability CVE-2024-23204 in Apple Shortcuts

Christi by Christi
February 22, 2024
in Mobile Security
Reading Time: 2 mins read
Critical flaw (CVE-2024-23204) in Apple Shortcuts: Attackers exploit ‘Expand URL’ function, transmitting sensitive data. Update software for protection.
Share on FacebookShare on Twitter

Cybersecurity firm Bitdefender has recently unearthed a significant security flaw in Apple’s popular automation app, Apple Shortcuts. This vulnerability, rated at 7.5 out of 10 in severity, poses a serious risk to user data and privacy.

You might also like

How Hackers Still Manage to Compromise MFA

BadBox Botnet Infects Over 190,000 Android Devices Worldwide

Massive Backdoor Infection Hits 1.3 Million Android-Based Streaming Devices

The Vulnerability: CVE-2024-23204

Bitdefender’s blog post, published on February 22, 2024, sheds light on this critical issue. The vulnerability, tracked as CVE-2024-23204, allows attackers to create malicious shortcut files that bypass Apple’s security framework for both macOS and iOS.

Apple Shortcuts: A Brief Overview

Apple Shortcuts is an automation app widely used by macOS and iOS users. It empowers individuals to streamline tasks by creating personalized workflows through visual programming. These workflows automate various actions, including app control, media management, messaging, and location-based tasks. Users can tailor workflows for file management, health tracking, web automation, education, and smart home integration, enhancing overall productivity and user experience.

The Vulnerability Explored

The flaw resides in the shortcut sharing/expanding mechanism within Apple’s Shortcuts community. This community serves as a hub for users to discover and expedite automation workflows and export and share their shortcuts.

CVE-2024-23204 enables attackers to stealthily import shortcuts that exploit the Transparency, Consent, and Control (TCC) security framework in macOS and iOS. This framework is crucial in safeguarding user privacy and security by mandating explicit permission before granting access to sensitive data or functionalities.

This flaw allows attackers to manipulate base64-encoded photo data and transmit the target to malicious websites.

The Attack Process

  1. Select Sensitive Data: Attackers identify sensitive information within the Shortcuts app.
  2. Import and Encode: The attacker imports the data and converts it using the base64 encode option.
  3. Transmit to Server: The encoded data is then forwarded to a server via the ‘Expand URL’ function.
  4. Data Capture: A Flask program captures the transmitted data, providing the attacker with a repository for exploitation.

Fortunately, Apple has addressed this issue in the following software versions:

  • macOS Sonoma 14.3
  • watchOS 10.3
  • iOS 17.3
  • iPadOS 17.3

The Vulnerability in Action:

This incident underscores the importance of ongoing security vigilance when using Apple Shortcuts. To safeguard your privacy:

  • Keep Software Updated: Ensure you are running the latest macOS, iPadOS, and watchOS versions.
  • Exercise Caution: Be wary when executing shortcuts from untrusted sources.
  • Regularly Check for Updates: Stay informed about Apple’s security patches.
Tags: appleIOSiPadOS
Previous Post

ESET Addresses High-Severity Vulnerability CVE-2024-0353 in Windows Products

Next Post

Microsoft Unveils PyRIT an AI Security Tool for Red Teaming

Christi

Christi

Christi began her InfoSec carrier at the Illinois Institute of Technology where she received her Bachelor of Science degree in Applied Cybersecurity and Information Technology. Her passions include learning about new threats, data breaches, running, and playing with her dog, Pablo.

Recommended For You

How Hackers Still Manage to Compromise MFA

How Hackers Still Manage to Compromise MFA

March 6, 2026
Discover how the BadBox botnet infects 190,000+ Android devices, compromising smart TVs and smartphones across multiple countries with dangerous malware.

BadBox Botnet Infects Over 190,000 Android Devices Worldwide

December 20, 2024

Massive Backdoor Infection Hits 1.3 Million Android-Based Streaming Devices

September 16, 2024

Cybercriminals Target Mobile Users in the Czech Republic with Phishing Campaigns Leveraging Progressive Web Applications

August 20, 2024

LianSpy: New Android Spyware Targeting Russian Users

August 7, 2024

New Mandrake Android Malware Variant Evades Detection on Google Play

July 29, 2024

Related News

Malicious Chrome Extensions Steal AI Data and Hijack Revenue in DarkSpectre Campaign

Malicious Chrome Extensions Steal AI Data and Hijack Revenue in DarkSpectre Campaign

January 30, 2026
KPMG Netherlands Listed as Victim by Nova Ransomware Group

KPMG Netherlands Listed as Victim by Nova Ransomware Group

January 24, 2026
RansomHouse Claims Breach of Key Apple Assembler Luxshare

RansomHouse Claims Breach of Key Apple Assembler Luxshare

January 20, 2026
ZeroSecurity - Information Security News

We cover the latest in technology news, Crypto, Artificial Intelligence, and the threat trends impacting these sectors.

Categories

Piracy

Tutorials

Programming

Malware Analysis

Downloads

  • Contact us
  • Press
  • Writers
  • Privacy Policy
  • Terms of Service

© 2026 ZeroSecurity, All Rights Reserved.

No Result
View All Result
  • Home
  • Security
    • Tools
  • Exploits
  • Data Breaches
  • Malware
  • Privacy
  • Mobile Security
  • Contact Us
    • Press
  • Privacy Policy

© 2026 ZeroSecurity, All Rights Reserved.

This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.