CVE-2024-27828
21Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 7epss 0.3%
exploitation probability
0.3%top 82% of all CVEs
observed exploitation
nono source reports it
In short
A memory handling flaw in Apple operating systems allows malicious apps to run code with the highest system privileges (kernel level). This is critical because it gives attackers complete control over your device.
Technical detail
Out-of-bounds memory access vulnerability (CWE-786, CWE-788) in iOS, iPadOS, tvOS, visionOS, and watchOS allows a malicious app to execute arbitrary code with kernel privileges. The attack requires the app to be installed on the device; the vulnerability is fixed through improved memory bounds checking in the affected OS versions.
Summary generated and translated by AI from the official description.
The issue was addressed with improved memory handling. This issue is fixed in iOS 17.5 and iPadOS 17.5, tvOS 17.5, visionOS 1.2, watchOS 10.5. An app may be able to execute arbitrary code with kernel privileges.
CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
References
http://seclists.org/fulldisclosure/2024/Jun/5https://support.apple.com/en-us/120901https://support.apple.com/en-us/120902https://support.apple.com/en-us/120905https://support.apple.com/en-us/120906https://support.apple.com/en-us/HT214101https://support.apple.com/en-us/HT214102https://support.apple.com/en-us/HT214104https://support.apple.com/en-us/HT214108https://support.apple.com/kb/HT214101https://support.apple.com/kb/HT214102https://support.apple.com/kb/HT214104