CVE-2024-40771

The issue was addressed with improved memory handling. This issue is fixed in macOS Sonoma 14.5, iOS 16.7.8 and iPadOS 16.7.8, iOS 17.5 and iPadOS 17.5, macOS Monterey 12.7.5, watchOS 10.5, tvOS 17.5, macOS Ventura 13.6.7, visionOS 1.2. An app may be able to execute arbitrary code with kernel privileges.
References
Link Resource
https://support.apple.com/en-us/120898 Vendor Advisory Release Notes
https://support.apple.com/en-us/120899 Vendor Advisory Release Notes
https://support.apple.com/en-us/120900 Vendor Advisory Release Notes
https://support.apple.com/en-us/120901 Vendor Advisory Release Notes
https://support.apple.com/en-us/120902 Vendor Advisory Release Notes
https://support.apple.com/en-us/120903 Vendor Advisory Release Notes
https://support.apple.com/en-us/120905 Vendor Advisory Release Notes
https://support.apple.com/en-us/120906 Vendor Advisory Release Notes
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:tvos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:visionos:*:*:*:*:*:*:*:*

History

14 Mar 2025, 13:43

Type Values Removed Values Added
First Time Apple
Apple iphone Os
Apple tvos
Apple macos
Apple ipados
Apple visionos
CVSS v2 : unknown
v3 : 8.4
v2 : unknown
v3 : 7.8
References () https://support.apple.com/en-us/120898 - () https://support.apple.com/en-us/120898 - Vendor Advisory, Release Notes
References () https://support.apple.com/en-us/120899 - () https://support.apple.com/en-us/120899 - Vendor Advisory, Release Notes
References () https://support.apple.com/en-us/120900 - () https://support.apple.com/en-us/120900 - Vendor Advisory, Release Notes
References () https://support.apple.com/en-us/120901 - () https://support.apple.com/en-us/120901 - Vendor Advisory, Release Notes
References () https://support.apple.com/en-us/120902 - () https://support.apple.com/en-us/120902 - Vendor Advisory, Release Notes
References () https://support.apple.com/en-us/120903 - () https://support.apple.com/en-us/120903 - Vendor Advisory, Release Notes
References () https://support.apple.com/en-us/120905 - () https://support.apple.com/en-us/120905 - Vendor Advisory, Release Notes
References () https://support.apple.com/en-us/120906 - () https://support.apple.com/en-us/120906 - Vendor Advisory, Release Notes
CPE cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:visionos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:tvos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
CWE NVD-CWE-noinfo

16 Jan 2025, 17:15

Type Values Removed Values Added
Summary
  • (es) El problema se solucionó con una gestión de memoria mejorada. Este problema se solucionó en macOS Sonoma 14.5, iOS 16.7.8 y iPadOS 16.7.8, iOS 17.5 y iPadOS 17.5, macOS Monterey 12.7.5, watchOS 10.5, tvOS 17.5, macOS Ventura 13.6.7 y visionOS 1.2. Es posible que una aplicación pueda ejecutar código arbitrario con privilegios de kernel.
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 8.4
CWE CWE-863

15 Jan 2025, 20:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-01-15 20:15

Updated : 2025-03-14 13:43


NVD link : CVE-2024-40771

Mitre link : CVE-2024-40771

CVE.ORG link : CVE-2024-40771


JSON object : View

Products Affected

apple

  • macos
  • visionos
  • tvos
  • ipados
  • iphone_os
CWE
NVD-CWE-noinfo CWE-863

Incorrect Authorization