CVE-2024-23255
macOS vulnerability analysis and mitigation

Overview

An authentication vulnerability (CVE-2024-23255) was discovered affecting Apple's Photos application in macOS Sonoma, iOS 17.4, and iPadOS 17.4. The vulnerability allows unauthorized access to photos stored in the Hidden Photos Album without proper authentication. This security issue was reported by security researcher Harsh Tyagi and was addressed by Apple in their March 2024 security updates (Apple Advisory).

Technical details

The vulnerability stems from an authentication issue in the Photos application's state management system. Apple addressed this security flaw by implementing improved state management mechanisms. The vulnerability has been assigned a CVSS v3.1 base score of 2.4 (LOW) by NIST with vector string CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N, though CISA-ADP assessed it with a higher CVSS score of 9.1 (CRITICAL) with vector string CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N (NVD).

Impact

The vulnerability allows unauthorized users to view photos stored in the Hidden Photos Album, potentially exposing private and sensitive images that users specifically chose to hide from normal access. This represents a significant privacy breach for users who rely on the Hidden Photos Album feature to protect sensitive content (Apple Advisory).

Exploitability

The vulnerability requires physical access to the device to be exploited. No active exploits have been reported in the wild, and Apple has addressed the issue through security updates in macOS Sonoma 14.4, iOS 17.4, and iPadOS 17.4 (Apple Advisory).

Mitigation and workarounds

Apple has released patches to address this vulnerability in macOS Sonoma 14.4, iOS 17.4, and iPadOS 17.4. Users are strongly advised to update their devices to these versions or later to protect against unauthorized access to their Hidden Photos Album. No alternative workarounds have been published (Apple Advisory).

Additional resources


SourceThis report was generated using AI

Related macOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-86917HIGH7.8
  • macOS logomacOS
  • Kernel
NoYesSep 14, 2026
CVE-2026-86924MEDIUM5.5
  • macOS logomacOS
  • MobileAccessoryUpdater
NoYesSep 14, 2026
CVE-2026-86910MEDIUM5.5
  • macOS logomacOS
  • APFS
NoYesSep 14, 2026
CVE-2026-86902MEDIUM5.5
  • macOS logomacOS
  • NSDocument
NoYesSep 14, 2026
CVE-2026-86891LOW3.5
  • macOS logomacOS
  • Core Bluetooth
NoYesSep 14, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management