Memory Corruption Vulnerability in Apple Operating Systems and Safari
CVE-2024-54543

8.8HIGH

Key Information:

Vendor
Apple
Status
Vendor
CVE Published:
27 January 2025

Summary

A memory corruption vulnerability exists in various Apple operating systems and the Safari browser due to improper memory handling. This vulnerability can be exploited through maliciously crafted web content, potentially leading to unexpected application behavior. The issue has been addressed in multiple Apple product updates, including visionOS, iOS, iPadOS, watchOS, tvOS, and macOS. Users are encouraged to update their devices to the latest versions to safeguard against this vulnerability.

Affected Version(s)

iOS and iPadOS < 18.2

macOS < 15.2

Safari < 18.2

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.