A timing side-channel issue was addressed with improvements to constant-time computation in cryptographic functions. This issue is fixed in macOS Sonoma 14.3, watchOS 10.3, tvOS 17.3, iOS 17.3 and iPadOS 17.3. An attacker may be able to decrypt legacy RSA PKCS#1 v1.5 ciphertexts without having the private key.
History

Tue, 04 Nov 2025 19:30:00 +0000


Fri, 14 Feb 2025 08:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published: 2024-01-23T00:25:38.999Z

Updated: 2025-11-04T18:24:24.383Z

Reserved: 2024-01-12T22:22:21.477Z

Link: CVE-2024-23218

cve-icon Vulnrichment

Updated: 2025-11-04T18:24:24.383Z

cve-icon NVD

Status : Modified

Published: 2024-01-23T01:15:11.403

Modified: 2025-11-04T19:16:36.173

Link: CVE-2024-23218

cve-icon Redhat

No data.