CVE-2024-54499

HIGH

Apple iPadOS < 18.2 - Use-After-Free via Maliciously Crafted Image

Title source: llm
STIX 2.1

Description

A use-after-free issue was addressed with improved memory management. This issue is fixed in iOS 18.2 and iPadOS 18.2, macOS Sequoia 15.2, tvOS 18.2, visionOS 2.2, watchOS 11.2. Processing a maliciously crafted image may lead to arbitrary code execution.

References (5)

Core 5
Core References
Release Notes, Vendor Advisory
https://support.apple.com/en-us/121837
Release Notes, Vendor Advisory
https://support.apple.com/en-us/121839
Release Notes, Vendor Advisory
https://support.apple.com/en-us/121843
Release Notes, Vendor Advisory
https://support.apple.com/en-us/121844

Scores

CVSS v3 8.8
EPSS 0.0024
EPSS Percentile 47.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-416
Status published
Products (11)
Apple/iOS and iPadOS < 18.2
apple/ipados < 18.2
apple/iphone_os < 18.2
apple/macos < 15.2
Apple/macOS < 15.2
apple/tvos < 18.2
Apple/tvOS < 18.2
apple/visionos < 2.2
Apple/visionOS < 2.2
apple/watchos < 11.2
... and 1 more
Published Jan 27, 2025
Tracked Since Feb 18, 2026