CVE-2024-40782

A use-after-free issue was addressed with improved memory management. This issue is fixed in iOS 16.7.9 and iPadOS 16.7.9, Safari 17.6, iOS 17.6 and iPadOS 17.6, watchOS 10.6, tvOS 17.6, visionOS 1.3, macOS Sonoma 14.6. Processing maliciously crafted web content may lead to an unexpected process crash.
References
Link Resource
http://seclists.org/fulldisclosure/2024/Jul/15 Mailing List
http://seclists.org/fulldisclosure/2024/Jul/16 Mailing List
http://seclists.org/fulldisclosure/2024/Jul/17 Mailing List
http://seclists.org/fulldisclosure/2024/Jul/18 Mailing List
http://seclists.org/fulldisclosure/2024/Jul/21 Mailing List
http://seclists.org/fulldisclosure/2024/Jul/22 Mailing List
http://seclists.org/fulldisclosure/2024/Jul/23 Mailing List
https://support.apple.com/en-us/HT214116 Vendor Advisory
https://support.apple.com/en-us/HT214117 Vendor Advisory
https://support.apple.com/en-us/HT214119 Vendor Advisory
https://support.apple.com/en-us/HT214121 Vendor Advisory
https://support.apple.com/en-us/HT214122 Vendor Advisory
https://support.apple.com/en-us/HT214123 Vendor Advisory
https://support.apple.com/en-us/HT214124 Vendor Advisory
http://seclists.org/fulldisclosure/2024/Jul/15 Mailing List
http://seclists.org/fulldisclosure/2024/Jul/16 Mailing List
http://seclists.org/fulldisclosure/2024/Jul/17 Mailing List
http://seclists.org/fulldisclosure/2024/Jul/18 Mailing List
http://seclists.org/fulldisclosure/2024/Jul/21 Mailing List
http://seclists.org/fulldisclosure/2024/Jul/22 Mailing List
http://seclists.org/fulldisclosure/2024/Jul/23 Mailing List
https://support.apple.com/en-us/HT214116 Vendor Advisory
https://support.apple.com/en-us/HT214117 Vendor Advisory
https://support.apple.com/en-us/HT214119 Vendor Advisory
https://support.apple.com/en-us/HT214121 Vendor Advisory
https://support.apple.com/en-us/HT214122 Vendor Advisory
https://support.apple.com/en-us/HT214123 Vendor Advisory
https://support.apple.com/en-us/HT214124 Vendor Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:apple:safari:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:tvos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:visionos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:watchos:*:*:*:*:*:*:*:*

History

10 Dec 2024, 14:40

Type Values Removed Values Added
First Time Apple visionos
Apple tvos
Apple macos
Apple ipados
Apple iphone Os
Apple safari
Apple
Apple watchos
References () http://seclists.org/fulldisclosure/2024/Jul/15 - () http://seclists.org/fulldisclosure/2024/Jul/15 - Mailing List
References () http://seclists.org/fulldisclosure/2024/Jul/16 - () http://seclists.org/fulldisclosure/2024/Jul/16 - Mailing List
References () http://seclists.org/fulldisclosure/2024/Jul/17 - () http://seclists.org/fulldisclosure/2024/Jul/17 - Mailing List
References () http://seclists.org/fulldisclosure/2024/Jul/18 - () http://seclists.org/fulldisclosure/2024/Jul/18 - Mailing List
References () http://seclists.org/fulldisclosure/2024/Jul/21 - () http://seclists.org/fulldisclosure/2024/Jul/21 - Mailing List
References () http://seclists.org/fulldisclosure/2024/Jul/22 - () http://seclists.org/fulldisclosure/2024/Jul/22 - Mailing List
References () http://seclists.org/fulldisclosure/2024/Jul/23 - () http://seclists.org/fulldisclosure/2024/Jul/23 - Mailing List
References () https://support.apple.com/en-us/HT214116 - () https://support.apple.com/en-us/HT214116 - Vendor Advisory
References () https://support.apple.com/en-us/HT214117 - () https://support.apple.com/en-us/HT214117 - Vendor Advisory
References () https://support.apple.com/en-us/HT214119 - () https://support.apple.com/en-us/HT214119 - Vendor Advisory
References () https://support.apple.com/en-us/HT214121 - () https://support.apple.com/en-us/HT214121 - Vendor Advisory
References () https://support.apple.com/en-us/HT214122 - () https://support.apple.com/en-us/HT214122 - Vendor Advisory
References () https://support.apple.com/en-us/HT214123 - () https://support.apple.com/en-us/HT214123 - Vendor Advisory
References () https://support.apple.com/en-us/HT214124 - () https://support.apple.com/en-us/HT214124 - Vendor Advisory
CPE cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:watchos:*:*:*:*:*:*:*:*
cpe:2.3:a:apple:safari:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:tvos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:visionos:*:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : 9.8
v2 : unknown
v3 : 6.5

Information

Published : 2024-07-29 23:15

Updated : 2024-12-10 14:40


NVD link : CVE-2024-40782

Mitre link : CVE-2024-40782

CVE.ORG link : CVE-2024-40782


JSON object : View

Products Affected

apple

  • watchos
  • macos
  • visionos
  • tvos
  • safari
  • ipados
  • iphone_os
CWE
CWE-416

Use After Free