CVSS 3.1 Score 5.9 of 10 (medium)


Published Mar 8, 2024
Updated: Mar 14, 2024


CVE-2024-23277 is a cyber vulnerability that affects various products, including uBrjen, ttJhXI, ttJhXF, tyi2Co, uy72ys, uy72yt, ttJhXH, ttJhXG, tPHKIZ, tPHKIY, tyFUDu, uS2iyn, u2fuSj, syj3pz, uS2iyo, and tza3Y5. This vulnerability allows an attacker in a privileged network position to inject keystrokes by spoofing a keyboard. The issue has been addressed and fixed in macOS Sonoma 14.4, iOS 17.4 and iPadOS 17.4. The vulnerability is rated as medium severity with a base score of 5.9 according to It requires no privileges and has no user interaction required. The attack vector is through the network and the integrity impact is high while the confidentiality impact is none. The exploitability score is 2.2 out of 10. Organizations using the affected products should update to the fixed versions in order to remediate this vulnerability and mitigate potential risks to their systems and data.

Explore Beyond the CVE Basics with Recorded Future's Vulnerability Intelligence

Note: This is just a basic overview providing quick insights into CVE-2024-23277 information. Gain full access to comprehensive CVE data, risk scores, prioritization, and mitigation data through Recorded Future's Vulnerability Intelligence:
  • Prioritize with Risk-Based Scoring
  • Explore the Extensive Vulnerability Database
  • Receive Early Alerts on Emerging CVEs
  • Focus on Critical Exploitable Vulnerabilities
  • Streamline Remediation with Integration Options