Out-of-Bounds Access Vulnerability in Apple Products
CVE-2024-54478

6.5MEDIUM

Key Information:

Vendor
Apple
Status
Vendor
CVE Published:
27 January 2025

Summary

An out-of-bounds access issue in Apple's operating systems may allow the processing of maliciously crafted web content to lead to an unexpected process crash. This vulnerability affects various versions of iPadOS, iOS, macOS, visionOS, tvOS, and watchOS. Apple has addressed this issue with improved bounds checking in the latest updates, ensuring enhanced security for users and preventing potential exploitation.

Affected Version(s)

iOS and iPadOS < 18.2

iPadOS < 17.7

macOS < 15.2

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.