Memory Disclosure Vulnerability in Apple Devices
CVE-2024-54500

5.5MEDIUM

Key Information:

Vendor
Apple
Vendor
CVE Published:
12 December 2024

Summary

A vulnerability has been identified that affects the processing of maliciously crafted images on various Apple platforms. This issue can allow an attacker to gain access to sensitive process memory. Apple has addressed this vulnerability with improved checks in multiple product versions, including iPadOS, macOS, watchOS, and others, ensuring enhanced security for users. It highlights the necessity for timely updates and vigilance against potential exploits targeting image handling capabilities.

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

.