Cyber Resilience

CVE-2024-44207

Apple Ipados ≤ 18.0.1

Published
04 October 2024
Modified
03 November 2025
Patch / advisory
CVSS Score v3.1 4.3
Click a component to see what it means
Raw vectorCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
EPSS Score 0.090 95th percentile
Risk Priority 46 floored blend · peak EPSS

Summary

CVE-2024-44207 is a medium-severity an unspecified weakness vulnerability in Apple Ipados. Its CVSS base score is 4.3 (Medium).

Operationally, ranked in the top 5% of CVEs by exploit likelihood; it is not currently listed in the CISA KEV catalog.

Deeper analysis AI-assisted summary

Synthesised by an AI model from the NVD description and linked references — a reading aid, not an authoritative source.

CVE-2024-44207 is a vulnerability in the Messages application on Apple's mobile platforms, where an incoming audio message could capture several seconds of audio from the device microphone before the microphone indicator activates. The flaw was caused by inadequate validation checks and is fixed in iOS 18.0.1 and iPadOS 18.0.1. It carries a CVSS 4.3 score reflecting network attack vector, low complexity, and limited confidentiality impact.

An unauthenticated remote attacker can trigger the issue by sending a crafted audio message that the recipient opens or plays, resulting in brief unauthorized audio capture without immediate user notification. The attack requires user interaction and does not allow further system compromise or data modification.

Apple's security update for iOS 18.0.1 and iPadOS 18.0.1 resolves the problem through improved checks, as described in the vendor advisory at support.apple.com/en-us/121373. The corresponding disclosure appears on seclists.org.

The associated EPSS score remains low and essentially flat, indicating no significant post-disclosure exploitation interest.

EU & UK References

Vulnerability Data

This issue was addressed with improved checks. This issue is fixed in iOS 18.0.1 and iPadOS 18.0.1. Audio messages in Messages may be able to capture a few seconds of audio before the microphone indicator is activated.

CWE(s)

Related Threats

CVEs Like This One

CVE-2024-54503Same product: Apple Ipados
CVE-2025-46292Same product: Apple Ipados
CVE-2023-27959Same product: Apple Ipados
CVE-2023-40428Same product: Apple Ipados
CVE-2023-27970Same product: Apple Ipados
CVE-2025-43365Same product: Apple Ipados
CVE-2025-31227Same product: Apple Ipados
CVE-2026-20678Same product: Apple Ipados
CVE-2024-27807Same product: Apple Ipados
CVE-2025-43450Same product: Apple Ipados

Affected Assets

apple
ipados
≤ 18.0.1
apple
iphone os
≤ 18.0.1

Mitigating Controls

No mitigating controls mapped yet. The per-CVE control annotator has not reached this CVE.

References