CVE-2024-40771

HIGH

macOS Sonoma <14.5, iOS <16.7.8, iPadOS <16.7.8, watchOS <10.5, tvO...

Title source: llm
STIX 2.1

Description

The issue was addressed with improved memory handling. This issue is fixed in iOS 16.7.8 and iPadOS 16.7.8, iOS 17.5 and iPadOS 17.5, macOS Monterey 12.7.5, macOS Sonoma 14.5, macOS Ventura 13.6.7, tvOS 17.5, visionOS 1.2, watchOS 10.5. An app may be able to execute arbitrary code with kernel privileges.

References (8)

Core 8
Core References
Release Notes, Vendor Advisory
https://support.apple.com/en-us/120898
Release Notes, Vendor Advisory
https://support.apple.com/en-us/120899
Release Notes, Vendor Advisory
https://support.apple.com/en-us/120900
Release Notes, Vendor Advisory
https://support.apple.com/en-us/120901
Release Notes, Vendor Advisory
https://support.apple.com/en-us/120902
Release Notes, Vendor Advisory
https://support.apple.com/en-us/120903
Release Notes, Vendor Advisory
https://support.apple.com/en-us/120905
Release Notes, Vendor Advisory
https://support.apple.com/en-us/120906

Scores

CVSS v3 7.8
EPSS 0.0005
EPSS Percentile 16.9%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-863
Status published
Products (13)
Apple/iOS and iPadOS < 16.7.8
Apple/iOS and iPadOS < 17.5
apple/ipados < 16.7.8
apple/iphone_os < 16.7.8
Apple/macOS < 12.7.5
apple/macos < 13.6.7
Apple/macOS < 13.6.7
Apple/macOS < 14.5
apple/tvos < 17.5
Apple/tvOS < 17.5
... and 3 more
Published Jan 15, 2025
Tracked Since Feb 18, 2026