OktaOKTA-0FN7LLB
Okta Verify for iOS ContextExtension CVE-2024-10327 - Oct 24, 2024
UnratedCVE-2024-10327 · Published Oct 24, 2024
A vulnerability in Okta Verify for iOS versions 9.25.1 (beta) and 9.27.0 (including beta) allows push notification responses through the iOS ContextExtension feature to bypass proper authentication validation.
Affected versions
The source does not list versions here. See the source advisory for affected products and fixes.
Details and references
More Okta advisories
All Okta| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Apr 302025 | JWT Invalid Signature Validation in Auth0 Account Linking Extensions CVE-2025-46345 - Apr... | Unrated | No fix yet |
| Nov 12024 | Okta AD/LDAP Delegated Authentication - Username Above 52 Characters Security Advisory... | Unrated | No fix yet |
| Nov 12024 | Okta Verify Desktop MFA for Windows Passwordless Login CVE-2024-9191 - Nov 1, 2024 | Unrated | No fix yet |
| Oct 42024 | Okta Classic Application Sign-On Policy Bypass - Oct 4, 2024 | Unrated | No fix yet |
| Aug 72024 | Okta Verify for Windows Privilege Escalation CVE-2024-7061 - Aug 7, 2024 | Unrated | No fix yet |
| Jul 222024 | Okta Browser Plugin Reflected Cross-Site Scripting CVE-2024-0981 - Jul 22, 2024 | Unrated | No fix yet |