CVE-2024-27840
21Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 7.5epss 0.3%
exploitation probability
0.3%top 83% of all CVEs
observed exploitation
nono source reports it
In short
A flaw in memory handling allows an attacker who already has control of the kernel to bypass protections that prevent unauthorized access to kernel memory. This matters because it removes a critical security barrier designed to isolate the operating system from being further compromised.
Technical detail
CWE-786 memory handling vulnerability affecting Apple's kernel. Attack requires prior kernel code execution; allows bypass of kernel memory protections through memory handling defects. Mitigated through improved memory handling across iOS, iPadOS, macOS, tvOS, visionOS, and watchOS platforms.
Summary generated and translated by AI from the official description.
The issue was addressed with improved memory handling. This issue is fixed in iOS 16.7.8 and iPadOS 16.7.8, iOS 17.5 and iPadOS 17.5, macOS Monterey 12.7.5, macOS Ventura 13.6.7, tvOS 17.5, visionOS 1.2, watchOS 10.5. An attacker that has already achieved kernel code execution may be able to bypass kernel memory protections.
CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H
References
http://seclists.org/fulldisclosure/2024/Jun/5https://support.apple.com/en-us/120898https://support.apple.com/en-us/120899https://support.apple.com/en-us/120900https://support.apple.com/en-us/120901https://support.apple.com/en-us/120902https://support.apple.com/en-us/120905https://support.apple.com/en-us/120906https://support.apple.com/en-us/HT214100https://support.apple.com/en-us/HT214101https://support.apple.com/en-us/HT214102https://support.apple.com/en-us/HT214104