CVE-2024-27812: Input Validation
A logic issue was addressed with improved file handling. This issue is fixed in visionOS 1.2. Processing web content may lead to a denial-of-service.
Other sources
AVEVideoEncoder. The issue was addressed with improved memory handling.
— Apple
CoreMedia. An out-of-bounds write issue was addressed with improved input validation.
— Apple
CoreMedia. The issue was addressed with improved checks.
— Apple
Disk Images. The issue was addressed with improved checks.
— Apple
Foundation. The issue was addressed with improved checks.
— Apple
Credit
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2024-40771
- CVE-2024-27817
- CVE-2024-27831
- CVE-2024-27832
- CVE-2024-27801
- CVE-2024-27836
- CVE-2024-27828
- CVE-2024-27840
- CVE-2024-27815
- CVE-2024-27811
- CVE-2024-27800
- CVE-2024-27802
- CVE-2024-27857
- CVE-2024-27844
- CVE-2024-27884
- CVE-2024-27856
- CVE-2024-27838
- CVE-2024-27808
- CVE-2024-27812
- CVE-2024-27850
- CVE-2024-27833
- CVE-2024-27851
- CVE-2024-27830
- CVE-2024-27820
Frequently Asked Questions
What is the severity of CVE-2024-27812?
CVE-2024-27812 has been categorized as a denial-of-service vulnerability.
How do I fix CVE-2024-27812?
To fix CVE-2024-27812, users should upgrade to visionOS version 1.2 or later.
What software is affected by CVE-2024-27812?
CVE-2024-27812 affects Apple visionOS versions prior to 1.2.
What type of issue is CVE-2024-27812?
CVE-2024-27812 is a logic issue related to file handling in WebKit.
Can CVE-2024-27812 be exploited remotely?
Yes, CVE-2024-27812 can potentially be exploited through processing malicious web content.