Vulnerabilities > CVE-2024-0230 - Unspecified vulnerability in Apple Magic Keyboard Firmware

047910
CVSS 2.4 - LOW
Attack vector
PHYSICAL
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
LOW
Integrity impact
NONE
Availability impact
NONE
low complexity
apple

Summary

A session management issue was addressed with improved checks. This issue is fixed in Magic Keyboard Firmware Update 2.0.6. An attacker with physical access to the accessory may be able to extract its Bluetooth pairing key and monitor Bluetooth traffic.

Vulnerable Configurations

Part Description Count
OS
Apple
1
Hardware
Apple
1