CVE-2024-27828
CVE-2024-27828
In short
A memory handling flaw in Apple operating systems allows malicious apps to run code with the highest system privileges (kernel level). This is critical because it gives attackers complete control over your device.
Technical detail
Out-of-bounds memory access vulnerability (CWE-786, CWE-788) in iOS, iPadOS, tvOS, visionOS, and watchOS allows a malicious app to execute arbitrary code with kernel privileges. The attack requires the app to be installed on the device; the vulnerability is fixed through improved memory bounds checking in the affected OS versions.
Summary generated and translated by AI from the official description.
The issue was addressed with improved memory handling. This issue is fixed in iOS 17.5 and iPadOS 17.5, tvOS 17.5, visionOS 1.2, watchOS 10.5. An app may be able to execute arbitrary code with kernel privileges.
CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
Want to know if your infrastructure is exposed to this?
Talk to TrueHacking →References
http://seclists.org/fulldisclosure/2024/Jun/5https://support.apple.com/en-us/120901https://support.apple.com/en-us/120902https://support.apple.com/en-us/120905https://support.apple.com/en-us/120906https://support.apple.com/en-us/HT214101https://support.apple.com/en-us/HT214102https://support.apple.com/en-us/HT214104https://support.apple.com/en-us/HT214108https://support.apple.com/kb/HT214101https://support.apple.com/kb/HT214102https://support.apple.com/kb/HT214104