CVE-2024-27880

An out-of-bounds read issue was addressed with improved input validation. This issue is fixed in iOS 17.7 and iPadOS 17.7, visionOS 2, watchOS 11, macOS Sequoia 15, iOS 18 and iPadOS 18, macOS Sonoma 14.7, tvOS 18. Processing a maliciously crafted file may lead to unexpected app termination.
References
Link Resource
https://support.apple.com/en-us/121238 Release Notes Vendor Advisory
https://support.apple.com/en-us/121240 Release Notes Vendor Advisory
https://support.apple.com/en-us/121246 Release Notes Vendor Advisory
https://support.apple.com/en-us/121247 Release Notes Vendor Advisory
https://support.apple.com/en-us/121248 Release Notes Vendor Advisory
https://support.apple.com/en-us/121249 Release Notes Vendor Advisory
https://support.apple.com/en-us/121250 Release Notes Vendor Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:visionos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:tvos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:watchos:*:*:*:*:*:*:*:*

History

24 Sep 2024, 16:34

Type Values Removed Values Added
CWE CWE-125
References () https://support.apple.com/en-us/121249 - () https://support.apple.com/en-us/121249 - Release Notes, Vendor Advisory
References () https://support.apple.com/en-us/121248 - () https://support.apple.com/en-us/121248 - Release Notes, Vendor Advisory
References () https://support.apple.com/en-us/121238 - () https://support.apple.com/en-us/121238 - Release Notes, Vendor Advisory
References () https://support.apple.com/en-us/121247 - () https://support.apple.com/en-us/121247 - Release Notes, Vendor Advisory
References () https://support.apple.com/en-us/121250 - () https://support.apple.com/en-us/121250 - Release Notes, Vendor Advisory
References () https://support.apple.com/en-us/121240 - () https://support.apple.com/en-us/121240 - Release Notes, Vendor Advisory
References () https://support.apple.com/en-us/121246 - () https://support.apple.com/en-us/121246 - Release Notes, Vendor Advisory
CPE cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:tvos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:watchos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:visionos:*:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.5
First Time Apple iphone Os
Apple
Apple ipados
Apple macos
Apple visionos
Apple tvos
Apple watchos

17 Sep 2024, 00:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-09-17 00:15

Updated : 2025-03-25 16:15


NVD link : CVE-2024-27880

Mitre link : CVE-2024-27880


JSON object : View

Products Affected

apple

  • tvos
  • watchos
  • ipados
  • macos
  • visionos
  • iphone_os
CWE
CWE-125

Out-of-bounds Read