CVE-2024-44258

This issue was addressed with improved handling of symlinks. This issue is fixed in iOS 17.7.1 and iPadOS 17.7.1, iOS 18.1 and iPadOS 18.1, tvOS 18.1, visionOS 2.1. Restoring a maliciously crafted backup file may lead to modification of protected system files.
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:tvos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:visionos:*:*:*:*:*:*:*:*

History

02 Apr 2026, 19:18

Type Values Removed Values Added
Summary (en) This issue was addressed with improved handling of symlinks. This issue is fixed in iOS 18.1 and iPadOS 18.1, iOS 17.7.1 and iPadOS 17.7.1, visionOS 2.1, tvOS 18.1. Restoring a maliciously crafted backup file may lead to modification of protected system files. (en) This issue was addressed with improved handling of symlinks. This issue is fixed in iOS 17.7.1 and iPadOS 17.7.1, iOS 18.1 and iPadOS 18.1, tvOS 18.1, visionOS 2.1. Restoring a maliciously crafted backup file may lead to modification of protected system files.

03 Nov 2025, 22:18

Type Values Removed Values Added
References
  • () http://seclists.org/fulldisclosure/2024/Oct/10 -
  • () http://seclists.org/fulldisclosure/2024/Oct/15 -
  • () http://seclists.org/fulldisclosure/2024/Oct/16 -
  • () http://seclists.org/fulldisclosure/2024/Oct/9 -

30 Oct 2024, 18:28

Type Values Removed Values Added
CPE cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:tvos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:visionos:*:*:*:*:*:*:*:*
CWE CWE-59
First Time Apple iphone Os
Apple visionos
Apple
Apple tvos
Apple ipados
References () https://support.apple.com/en-us/121563 - () https://support.apple.com/en-us/121563 - Release Notes, Vendor Advisory
References () https://support.apple.com/en-us/121566 - () https://support.apple.com/en-us/121566 - Release Notes, Vendor Advisory
References () https://support.apple.com/en-us/121567 - () https://support.apple.com/en-us/121567 - Release Notes, Vendor Advisory
References () https://support.apple.com/en-us/121569 - () https://support.apple.com/en-us/121569 - Release Notes, Vendor Advisory
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.1

29 Oct 2024, 14:34

Type Values Removed Values Added
Summary
  • (es) Este problema se solucionó con un manejo mejorado de los enlaces simbólicos. Este problema se solucionó en iOS 18.1 y iPadOS 18.1, iOS 17.7.1 y iPadOS 17.7.1, visionOS 2.1 y tvOS 18.1. Restaurar un archivo de copia de seguridad manipulado con fines malintencionados puede provocar la modificación de archivos de sistema protegidos.

28 Oct 2024, 21:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-10-28 21:15

Updated : 2026-04-02 19:18


NVD link : CVE-2024-44258

Mitre link : CVE-2024-44258

CVE.ORG link : CVE-2024-44258


JSON object : View

Products Affected

apple

  • tvos
  • iphone_os
  • ipados
  • visionos
CWE
CWE-59

Improper Link Resolution Before File Access ('Link Following')