The issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14.5. An app may be able to execute arbitrary code out of its sandbox or with certain elevated privileges.
References
Link | Resource |
---|---|
http://seclists.org/fulldisclosure/2024/May/12 | Mailing List |
https://support.apple.com/en-us/HT214106 | Vendor Advisory |
https://support.apple.com/kb/HT214106 | Vendor Advisory |
http://seclists.org/fulldisclosure/2024/May/12 | Mailing List |
https://support.apple.com/en-us/HT214106 | Vendor Advisory |
https://support.apple.com/kb/HT214106 | Vendor Advisory |
Configurations
History
09 Dec 2024, 19:10
Type | Values Removed | Values Added |
---|---|---|
References | () http://seclists.org/fulldisclosure/2024/May/12 - Mailing List | |
References | () https://support.apple.com/en-us/HT214106 - Vendor Advisory | |
References | () https://support.apple.com/kb/HT214106 - Vendor Advisory | |
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 8.6 |
First Time |
Apple
Apple macos |
|
CWE | NVD-CWE-noinfo | |
CPE | cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:* |
21 Nov 2024, 09:05
Type | Values Removed | Values Added |
---|---|---|
References | () http://seclists.org/fulldisclosure/2024/May/12 - | |
References | () https://support.apple.com/en-us/HT214106 - | |
References | () https://support.apple.com/kb/HT214106 - |
03 Jul 2024, 01:50
Type | Values Removed | Values Added |
---|---|---|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 5.3 |
10 Jun 2024, 18:15
Type | Values Removed | Values Added |
---|---|---|
Summary |
|
|
References |
|
14 May 2024, 15:13
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-05-14 15:13
Updated : 2024-12-09 19:10
NVD link : CVE-2024-27813
Mitre link : CVE-2024-27813
CVE.ORG link : CVE-2024-27813
JSON object : View
Products Affected
apple
- macos
CWE