CVE-2024-23295: Input Validation
A permissions issue was addressed to help ensure Personas are always protected. This issue is fixed in visionOS 1.1. An unauthenticated user may be able to use an unprotected Persona.
Other sources
Accessibility. This issue was addressed with additional entitlement checks.
— Apple
ImageIO. A buffer overflow issue was addressed with improved memory handling.
— Apple
ImageIO. An out-of-bounds read was addressed with improved input validation.
— Apple
ImageIO. The issue was addressed with improved memory handling.
— Apple
Kernel. A memory corruption issue was addressed with improved validation.
— Apple
Credit
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2024-23295?
CVE-2024-23295 has a medium severity due to the permissions issue that can allow unauthenticated access to unprotected Personas.
How do I fix CVE-2024-23295?
To fix CVE-2024-23295, update your Apple visionOS installation to version 1.1 or later.
What does CVE-2024-23295 affect?
CVE-2024-23295 affects Apple visionOS versions prior to 1.1.
Who is impacted by CVE-2024-23295?
Users of Apple visionOS versions below 1.1 are impacted by CVE-2024-23295.
What type of vulnerability is CVE-2024-23295?
CVE-2024-23295 is classified as a permissions issue that could lead to unauthorized access.