CVE-2024-40771

The issue was addressed with improved memory handling. This issue is fixed in iOS 16.7.8 and iPadOS 16.7.8, iOS 17.5 and iPadOS 17.5, macOS Monterey 12.7.5, macOS Sonoma 14.5, macOS Ventura 13.6.7, tvOS 17.5, visionOS 1.2, watchOS 10.5. An app may be able to execute arbitrary code with kernel privileges.
References
Link Resource
https://support.apple.com/en-us/120898 Release Notes Vendor Advisory
https://support.apple.com/en-us/120899 Release Notes Vendor Advisory
https://support.apple.com/en-us/120900 Release Notes Vendor Advisory
https://support.apple.com/en-us/120901 Release Notes Vendor Advisory
https://support.apple.com/en-us/120902 Release Notes Vendor Advisory
https://support.apple.com/en-us/120903 Release Notes Vendor Advisory
https://support.apple.com/en-us/120905 Release Notes Vendor Advisory
https://support.apple.com/en-us/120906 Release Notes Vendor Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:tvos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:visionos:*:*:*:*:*:*:*:*

History

02 Apr 2026, 19:17

Type Values Removed Values Added
References () https://support.apple.com/en-us/120898 - Vendor Advisory, Release Notes () https://support.apple.com/en-us/120898 - Release Notes, Vendor Advisory
References () https://support.apple.com/en-us/120899 - Vendor Advisory, Release Notes () https://support.apple.com/en-us/120899 - Release Notes, Vendor Advisory
References () https://support.apple.com/en-us/120900 - Vendor Advisory, Release Notes () https://support.apple.com/en-us/120900 - Release Notes, Vendor Advisory
References () https://support.apple.com/en-us/120901 - Vendor Advisory, Release Notes () https://support.apple.com/en-us/120901 - Release Notes, Vendor Advisory
References () https://support.apple.com/en-us/120902 - Vendor Advisory, Release Notes () https://support.apple.com/en-us/120902 - Release Notes, Vendor Advisory
References () https://support.apple.com/en-us/120903 - Vendor Advisory, Release Notes () https://support.apple.com/en-us/120903 - Release Notes, Vendor Advisory
References () https://support.apple.com/en-us/120905 - Vendor Advisory, Release Notes () https://support.apple.com/en-us/120905 - Release Notes, Vendor Advisory
References () https://support.apple.com/en-us/120906 - Vendor Advisory, Release Notes () https://support.apple.com/en-us/120906 - Release Notes, Vendor Advisory
Summary (en) The issue was addressed with improved memory handling. This issue is fixed in macOS Sonoma 14.5, iOS 16.7.8 and iPadOS 16.7.8, iOS 17.5 and iPadOS 17.5, macOS Monterey 12.7.5, watchOS 10.5, tvOS 17.5, macOS Ventura 13.6.7, visionOS 1.2. An app may be able to execute arbitrary code with kernel privileges. (en) The issue was addressed with improved memory handling. This issue is fixed in iOS 16.7.8 and iPadOS 16.7.8, iOS 17.5 and iPadOS 17.5, macOS Monterey 12.7.5, macOS Sonoma 14.5, macOS Ventura 13.6.7, tvOS 17.5, visionOS 1.2, watchOS 10.5. An app may be able to execute arbitrary code with kernel privileges.

14 Mar 2025, 13:43

Type Values Removed Values Added
References () https://support.apple.com/en-us/120898 - () https://support.apple.com/en-us/120898 - Vendor Advisory, Release Notes
References () https://support.apple.com/en-us/120899 - () https://support.apple.com/en-us/120899 - Vendor Advisory, Release Notes
References () https://support.apple.com/en-us/120900 - () https://support.apple.com/en-us/120900 - Vendor Advisory, Release Notes
References () https://support.apple.com/en-us/120901 - () https://support.apple.com/en-us/120901 - Vendor Advisory, Release Notes
References () https://support.apple.com/en-us/120902 - () https://support.apple.com/en-us/120902 - Vendor Advisory, Release Notes
References () https://support.apple.com/en-us/120903 - () https://support.apple.com/en-us/120903 - Vendor Advisory, Release Notes
References () https://support.apple.com/en-us/120905 - () https://support.apple.com/en-us/120905 - Vendor Advisory, Release Notes
References () https://support.apple.com/en-us/120906 - () https://support.apple.com/en-us/120906 - Vendor Advisory, Release Notes
CWE NVD-CWE-noinfo
First Time Apple macos
Apple
Apple visionos
Apple ipados
Apple tvos
Apple iphone Os
CVSS v2 : unknown
v3 : 8.4
v2 : unknown
v3 : 7.8
CPE cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:visionos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:tvos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*

16 Jan 2025, 17:15

Type Values Removed Values Added
CWE CWE-863
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 8.4
Summary
  • (es) El problema se solucionó con una gestión de memoria mejorada. Este problema se solucionó en macOS Sonoma 14.5, iOS 16.7.8 y iPadOS 16.7.8, iOS 17.5 y iPadOS 17.5, macOS Monterey 12.7.5, watchOS 10.5, tvOS 17.5, macOS Ventura 13.6.7 y visionOS 1.2. Es posible que una aplicación pueda ejecutar código arbitrario con privilegios de kernel.

15 Jan 2025, 20:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-01-15 20:15

Updated : 2026-04-02 19:17


NVD link : CVE-2024-40771

Mitre link : CVE-2024-40771

CVE.ORG link : CVE-2024-40771


JSON object : View

Products Affected

apple

  • ipados
  • tvos
  • visionos
  • macos
  • iphone_os
CWE
NVD-CWE-noinfo CWE-863

Incorrect Authorization