Details have been revealed about a serious zero-click vulnerability in Apple 's Shortcuts app , which allows unauthorized access to sensitive user information.

The zero-click vulnerability, identified as CVE-2024-23204 (with CVSS score: 7.5), was patched by Apple on January 22, 2024, with the release of iOS 17.3, iPadOS 17.3, macOS Sonoma 14.3 and watchOS 10.3.
Read more: LockBit ransomware: Infects networks via ScreenConnect vulnerability
The iPhone maker reported that a shortcut could use sensitive data for certain actions without requiring user approval, stating that it had fixed it by adding an "additional security check."
Apple Shortcuts is a scripting app that allows users to create custom workflows, also known as macros, to perform specific tasks on their devices. It is a pre-installed app on iOS, iPadOS, macOS, and watchOS.
Bitdefender security researcher Jubaer Alnazi Jabin, who discovered and reported the Shortcuts bug, mentioned that this could be exploited to create a malicious shortcut that would violate Trusted Execution Environment (TCC) policies
The Trusted Execution Environment (TCC) is a security framework belonging to Apple and designed to protect user data from unauthorized access, without requiring prior appropriate permissions.
Specifically, the issue stems from a process known as “Expand URL,” which expands and cleans up shortened URLs using services like t.co and bit.ly. It also removes UTM tracking parameters.
Using this mechanism, it was possible to transfer data that has been encoded from the Base64 of a photo to a malicious website», explained Alnazi Jabin.
The method involves embedding any sensitive data (photos, contacts, files and pre‑flight data) into shortcuts. It is followed by their import, conversion to base64, and finally their transmission to the malicious server.

See more: Chinese tried to scam Apple with fake iPhones
Next, the extracted data is captured and stored as an image on the server using a application , paving the way for further exploitation.
The researcher reported that shortcuts can be extracted and shared among users, which is a common practice in the Shortcuts community. This sharing mechanism expands the potential reach of the vulnerability, as users import shortcuts without knowing possible vulnerabilities that may exist, such as CVE-2024-23204.
Source: thehackernews.com
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
