Description
A race condition was addressed with improved locking. This issue is fixed in iOS 16.7.8 and iPadOS 16.7.8, iOS 17.5 and iPadOS 17.5, macOS Monterey 12.7.5, macOS Sonoma 14.5, macOS Ventura 13.6.7, tvOS 17.5, visionOS 1.3, watchOS 10.5. An attacker in a privileged network position may be able to spoof network packets.
References (25)
Core 25
Core References
Mailing List, Third Party Advisory
http://seclists.org/fulldisclosure/2024/Jul/23
Release Notes, Vendor Advisory
https://support.apple.com/en-us/HT214100
Release Notes, Vendor Advisory
https://support.apple.com/en-us/HT214101
Release Notes, Vendor Advisory
https://support.apple.com/en-us/HT214102
Release Notes, Vendor Advisory
https://support.apple.com/en-us/HT214104
Release Notes, Vendor Advisory
https://support.apple.com/en-us/HT214105
Release Notes, Vendor Advisory
https://support.apple.com/en-us/HT214106
Release Notes, Vendor Advisory
https://support.apple.com/en-us/HT214107
Release Notes, Vendor Advisory
https://support.apple.com/en-us/HT214123
Release Notes, Vendor Advisory
https://support.apple.com/kb/HT214100
Release Notes, Vendor Advisory
https://support.apple.com/kb/HT214101
Release Notes, Vendor Advisory
https://support.apple.com/kb/HT214102
Release Notes, Vendor Advisory
https://support.apple.com/kb/HT214104
Release Notes, Vendor Advisory
https://support.apple.com/kb/HT214105
Release Notes, Vendor Advisory
https://support.apple.com/kb/HT214106
Release Notes, Vendor Advisory
https://support.apple.com/kb/HT214107
Vendor Advisory
https://support.apple.com/kb/HT214123
Scores
CVSS v3
5.9
EPSS
0.0019
EPSS Percentile
39.8%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-362
Status
published
Products (14)
Apple/iOS and iPadOS
< 16.7.8
Apple/iOS and iPadOS
< 17.5
apple/ipados
< 16.7.8
apple/iphone_os
< 16.7.8
apple/macos
< 12.7.5
Apple/macOS
< 12.7.5
Apple/macOS
< 13.6.7
Apple/macOS
< 14.5
apple/tvos
< 17.5
Apple/tvOS
< 17.5
... and 4 more
Published
Jul 29, 2024
Tracked Since
Feb 18, 2026