CVE-2024-27857

EUVD-2024-25050
An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in iOS 17.5 and iPadOS 17.5, macOS Sonoma 14.5, tvOS 17.5, visionOS 1.2. A remote attacker may be able to cause unexpected app termination or arbitrary code execution.
Code Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.8 HIGH
LOCAL
LOW
NONE
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 77%
Affected Products (NVD)
VendorProductVersion
appleipados
𝑥
< 17.5
appleiphone_os
𝑥
< 17.5
applemacos
14.0 ≤
𝑥
< 14.5
appletvos
𝑥
< 17.5
applevisionos
𝑥
< 1.2
𝑥
= Vulnerable software versions
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
VendorProductVersionSource
appletvos
1.0.0 ≤
𝑥
< 17.5
ADP
applemacos
1.0 ≤
𝑥
< 14.5
ADP
appleios
𝑥
< 17.5
ADP
appleipados
𝑥
< 17.5
ADP
applevisionos
𝑥
< 1.2
ADP