Apple devices and Safari: buffer overflow (CVE-2024-54508) #shorts

CVE

This CVE relates to a critical buffer overflow vulnerability affecting a wide range of Apple devices and their respective operating systems, including Safari and other platforms such as watchOS, visionOS, tvOS, macOS, iOS, and iPadOS. As a zero-day vulnerability, it remains exposed until properly addressed. The flaw is found in the way memory is handled, allowing attackers to potentially cause an application process to crash when users process maliciously crafted web content. This suggests that the vulnerability is situated within the web rendering framework. Though specific attack vectors and tools remain undisclosed, the broad scope of affected platforms and the nature of the flaw make it a significant security concern. It is critical for all users of impacted Apple devices to understand the potential risk of process interruption or performance degradation due to this exploit.

Watch the full video on YouTube: CVE-2024-54508

Remediation and exploitation details

This chain involves the following actors

This following systems are involved

Attack entry point

Remediation actions

Exploitation actions

Related Content

NOTE: The following related content has not been vetted and may be unsafe.

CVE database technical details

CVE ID
CVE-2024-54508
Description
The issue was addressed with improved memory handling. This issue is fixed in watchOS 11.2, visionOS 2.2, tvOS 18.2, macOS Sequoia 15.2, Safari 18.2, iOS 18.2 and iPadOS 18.2. Processing maliciously crafted web content may lead to an unexpected process crash.
Provider
apple
CWE / problem types
Processing maliciously crafted web content may lead to an unexpected process crash
Affected Software Versions
Apple:tvOS:[{'version': 'unspecified', 'status': 'affected', 'lessThan': '18.2', 'versionType': 'custom'}],Apple:visionOS:[{'version': 'unspecified', 'status': 'affected', 'lessThan': '2.2', 'versionType': 'custom'}],Apple:macOS:[{'version': 'unspecified', 'status': 'affected', 'lessThan': '15.2', 'versionType': 'custom'}],Apple:watchOS:[{'version': 'unspecified', 'status': 'affected', 'lessThan': '11.2', 'versionType': 'custom'}],Apple:iOS and iPadOS:[{'version': 'unspecified', 'status': 'affected', 'lessThan': '18.2', 'versionType': 'custom'}],Apple:Safari:[{'version': 'unspecified', 'status': 'affected', 'lessThan': '18.2', 'versionType': 'custom'}]
Date Published
2024-12-11T22:58:14.487Z
Last Updated
2024-12-16T18:37:55.936Z