CVE-2024-40776

A use-after-free issue was addressed with improved memory management. This issue is fixed in iOS 16.7.9 and iPadOS 16.7.9, Safari 17.6, iOS 17.6 and iPadOS 17.6, watchOS 10.6, tvOS 17.6, visionOS 1.3, macOS Sonoma 14.6. Processing maliciously crafted web content may lead to an unexpected process crash.
References
Link Resource
https://support.apple.com/en-us/HT214121 Release Notes Vendor Advisory
https://support.apple.com/en-us/HT214117 Release Notes Vendor Advisory
https://support.apple.com/en-us/HT214116 Release Notes Vendor Advisory
https://support.apple.com/en-us/HT214124 Release Notes Vendor Advisory
https://support.apple.com/en-us/HT214119 Release Notes Vendor Advisory
https://support.apple.com/en-us/HT214123 Release Notes Vendor Advisory
https://support.apple.com/en-us/HT214122 Release Notes Vendor Advisory
http://seclists.org/fulldisclosure/2024/Jul/16 Mailing List Third Party Advisory
http://seclists.org/fulldisclosure/2024/Jul/15 Mailing List Third Party Advisory
http://seclists.org/fulldisclosure/2024/Jul/23 Mailing List Third Party Advisory
http://seclists.org/fulldisclosure/2024/Jul/21 Mailing List Third Party Advisory
http://seclists.org/fulldisclosure/2024/Jul/17 Mailing List Third Party Advisory
http://seclists.org/fulldisclosure/2024/Jul/22 Mailing List Third Party Advisory
http://seclists.org/fulldisclosure/2024/Jul/18 Mailing List Third Party Advisory
https://www.secpod.com/blog/apple-fixes-multiple-security-vulnerabilities-in-july-2024-updates/ Third Party Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*

Configuration 2 (hide)

OR cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*

Configuration 3 (hide)

cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*

Configuration 4 (hide)

cpe:2.3:a:apple:safari:*:*:*:*:*:*:*:*

Configuration 5 (hide)

cpe:2.3:o:apple:watchos:*:*:*:*:*:*:*:*

Configuration 6 (hide)

cpe:2.3:o:apple:tvos:*:*:*:*:*:*:*:*

Configuration 7 (hide)

cpe:2.3:o:apple:visionos:*:*:*:*:*:*:*:*

History

20 Aug 2024, 15:19

Type Values Removed Values Added
First Time Apple
Apple ipados
Apple macos
Apple iphone Os
Apple safari
Apple visionos
Apple tvos
Apple watchos
CPE cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:tvos:*:*:*:*:*:*:*:*
cpe:2.3:a:apple:safari:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:watchos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:visionos:*:*:*:*:*:*:*:*
CWE CWE-416
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 4.3
References () http://seclists.org/fulldisclosure/2024/Jul/18 - () http://seclists.org/fulldisclosure/2024/Jul/18 - Mailing List, Third Party Advisory
References () https://support.apple.com/en-us/HT214123 - () https://support.apple.com/en-us/HT214123 - Release Notes, Vendor Advisory
References () https://support.apple.com/en-us/HT214122 - () https://support.apple.com/en-us/HT214122 - Release Notes, Vendor Advisory
References () https://support.apple.com/en-us/HT214116 - () https://support.apple.com/en-us/HT214116 - Release Notes, Vendor Advisory
References () http://seclists.org/fulldisclosure/2024/Jul/21 - () http://seclists.org/fulldisclosure/2024/Jul/21 - Mailing List, Third Party Advisory
References () http://seclists.org/fulldisclosure/2024/Jul/22 - () http://seclists.org/fulldisclosure/2024/Jul/22 - Mailing List, Third Party Advisory
References () https://support.apple.com/en-us/HT214117 - () https://support.apple.com/en-us/HT214117 - Release Notes, Vendor Advisory
References () http://seclists.org/fulldisclosure/2024/Jul/17 - () http://seclists.org/fulldisclosure/2024/Jul/17 - Mailing List, Third Party Advisory
References () https://support.apple.com/en-us/HT214119 - () https://support.apple.com/en-us/HT214119 - Release Notes, Vendor Advisory
References () http://seclists.org/fulldisclosure/2024/Jul/16 - () http://seclists.org/fulldisclosure/2024/Jul/16 - Mailing List, Third Party Advisory
References () https://www.secpod.com/blog/apple-fixes-multiple-security-vulnerabilities-in-july-2024-updates/ - () https://www.secpod.com/blog/apple-fixes-multiple-security-vulnerabilities-in-july-2024-updates/ - Third Party Advisory
References () http://seclists.org/fulldisclosure/2024/Jul/15 - () http://seclists.org/fulldisclosure/2024/Jul/15 - Mailing List, Third Party Advisory
References () http://seclists.org/fulldisclosure/2024/Jul/23 - () http://seclists.org/fulldisclosure/2024/Jul/23 - Mailing List, Third Party Advisory
References () https://support.apple.com/en-us/HT214124 - () https://support.apple.com/en-us/HT214124 - Release Notes, Vendor Advisory
References () https://support.apple.com/en-us/HT214121 - () https://support.apple.com/en-us/HT214121 - Release Notes, Vendor Advisory

13 Aug 2024, 18:15

Type Values Removed Values Added
References
  • () https://www.secpod.com/blog/apple-fixes-multiple-security-vulnerabilities-in-july-2024-updates/ -

30 Jul 2024, 02:15

Type Values Removed Values Added
References
  • () http://seclists.org/fulldisclosure/2024/Jul/18 -
  • () http://seclists.org/fulldisclosure/2024/Jul/22 -
  • () http://seclists.org/fulldisclosure/2024/Jul/21 -
  • () http://seclists.org/fulldisclosure/2024/Jul/17 -
  • () http://seclists.org/fulldisclosure/2024/Jul/16 -
  • () http://seclists.org/fulldisclosure/2024/Jul/15 -
  • () http://seclists.org/fulldisclosure/2024/Jul/23 -

29 Jul 2024, 23:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-07-29 23:15

Updated : 2024-10-27 01:35


NVD link : CVE-2024-40776

Mitre link : CVE-2024-40776


JSON object : View

Products Affected

apple

  • watchos
  • tvos
  • ipados
  • safari
  • macos
  • visionos
  • iphone_os
CWE
CWE-416

Use After Free