{"dataType":"CVE_RECORD","cveMetadata":{"cveId":"CVE-2024-40778","assignerOrgId":"286789f9-fbc2-4510-9f9a-43facdede74c","state":"PUBLISHED","assignerShortName":"apple","dateReserved":"2024-07-10T17:11:04.688Z","datePublished":"2024-07-29T22:16:32.808Z","dateUpdated":"2026-04-02T18:09:32.265Z"},"containers":{"cna":{"problemTypes":[{"descriptions":[{"lang":"en","description":"Photos in the Hidden Photos Album may be viewed without authentication"}]}],"affected":[{"vendor":"Apple","product":"iOS and iPadOS","versions":[{"version":"0","status":"affected","lessThan":"16.7.9","versionType":"custom"},{"version":"0","status":"affected","lessThan":"17.6","versionType":"custom"}]},{"vendor":"Apple","product":"macOS","versions":[{"version":"0","status":"affected","lessThan":"14.6","versionType":"custom"}]}],"descriptions":[{"lang":"en","value":"An authentication issue was addressed with improved state management. This issue is fixed in iOS 16.7.9 and iPadOS 16.7.9, iOS 17.6 and iPadOS 17.6, macOS Sonoma 14.6. Photos in the Hidden Photos Album may be viewed without authentication."}],"references":[{"url":"https://support.apple.com/en-us/120908"},{"url":"https://support.apple.com/en-us/120909"},{"url":"https://support.apple.com/en-us/120911"}],"providerMetadata":{"orgId":"286789f9-fbc2-4510-9f9a-43facdede74c","shortName":"apple","dateUpdated":"2026-04-02T18:09:32.265Z"}},"adp":[{"problemTypes":[{"descriptions":[{"type":"CWE","cweId":"CWE-287","lang":"en","description":"CWE-287 Improper Authentication"}]}],"metrics":[{"cvssV3_1":{"scope":"UNCHANGED","version":"3.1","baseScore":3.3,"attackVector":"LOCAL","baseSeverity":"LOW","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","integrityImpact":"NONE","userInteraction":"NONE","attackComplexity":"LOW","availabilityImpact":"NONE","privilegesRequired":"LOW","confidentialityImpact":"LOW"}},{"other":{"type":"ssvc","content":{"timestamp":"2024-07-30T14:56:40.272211Z","id":"CVE-2024-40778","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2025-03-17T15:50:14.601Z"}},{"title":"CVE Program Container","references":[{"url":"https://support.apple.com/en-us/HT214117","tags":["x_transferred"]},{"url":"https://support.apple.com/en-us/HT214116","tags":["x_transferred"]},{"url":"https://support.apple.com/en-us/HT214119","tags":["x_transferred"]},{"url":"http://seclists.org/fulldisclosure/2024/Jul/16","tags":["x_transferred"]},{"url":"http://seclists.org/fulldisclosure/2024/Jul/17","tags":["x_transferred"]},{"url":"http://seclists.org/fulldisclosure/2024/Jul/18","tags":["x_transferred"]},{"url":"https://support.apple.com/kb/HT214119"},{"url":"https://support.apple.com/kb/HT214117"},{"url":"https://support.apple.com/kb/HT214116"}],"providerMetadata":{"orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE","dateUpdated":"2025-11-04T17:22:38.873Z"}}]},"dataVersion":"5.2"}