An authentication issue was addressed with improved state management. This issue is fixed in macOS Sonoma 14.4, iOS 17.4 and iPadOS 17.4. Photos in the Hidden Photos Album may be viewed without authentication.
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.
Link | Tags |
---|---|
https://support.apple.com/en-us/HT214081 | vendor advisory |
https://support.apple.com/en-us/HT214084 | vendor advisory |
http://seclists.org/fulldisclosure/2024/Mar/21 | mailing list |