CVE-2024-44252

HIGH

iPadOS < 17.7.1 - Arbitrary File Write via Malicious Backup Restore

Title source: llm
STIX 2.1

Description

A logic issue was addressed with improved file handling. This issue is fixed in iOS 17.7.1 and iPadOS 17.7.1, iOS 18.1 and iPadOS 18.1, tvOS 18.1, visionOS 2.1. Restoring a maliciously crafted backup file may lead to modification of protected system files.

Scores

CVSS v3 7.1
EPSS 0.0005
EPSS Percentile 17.0%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

Status published
Products (8)
Apple/iOS and iPadOS < 17.7.1
Apple/iOS and iPadOS < 18.1
apple/ipados < 17.7.1
apple/iphone_os < 17.7.1
apple/tvos < 18.1
Apple/tvOS < 18.1
apple/visionos < 2.1
Apple/visionOS < 2.1
Published Oct 28, 2024
Tracked Since Feb 18, 2026