Apple has rolled out important updates for iOS and iPadOS to fix two significant security vulnerabilities, including one that could potentially expose users’ passwords through the VoiceOver feature.
The flaw, identified as CVE-2024-44204, stems from a logic issue in the Passwords app and affects a wide range of iPhone and iPad models. According to Apple’s statement, the issue allowed saved passwords to be spoken aloud by VoiceOver, the accessibility tool. The company has resolved the problem by enhancing validation procedures.
Devices affected by this vulnerability include:
- iPhone XS and newer models
- iPad Pro 13-inch
- iPad Pro 12.9-inch (3rd generation and later)
- iPad Pro 11-inch (1st generation and later)
- iPad Air (3rd generation and later)
- iPad (7th generation and later)
- iPad mini (5th generation and later)
Additionally, Apple addressed another security issue (CVE-2024-44207) that impacted the iPhone 16 series. This vulnerability allowed audio to be recorded just before the microphone indicator light turned on, affecting the Media Session component. Apple credited Michael Jimenez and an anonymous researcher for bringing this to light.
Apple has fixed this issue by implementing improved security checks. To ensure protection against these vulnerabilities, users are encouraged to update their devices to iOS 18.0.1 or iPadOS 18.0.1.