CVE-2024-27823: Race Condition
A race condition was addressed with improved locking. This issue is fixed in iOS 16.7.8 and iPadOS 16.7.8, iOS 17.5 and iPadOS 17.5, macOS Monterey 12.7.5, macOS Sonoma 14.5, macOS Ventura 13.6.7, tvOS 17.5, visionOS 1.3, watchOS 10.5. An attacker in a privileged network position may be able to spoof network packets.
Other sources
AirDrop. This issue was addressed through improved state management.
— Apple
Apple Neural Engine. The issue was addressed with improved memory handling.
— Apple
AppleAVD. The issue was addressed with improved memory handling.
— Apple
AppleMobileFileIntegrity. A downgrade issue affecting Intel-based Mac computers was addressed with additional code-signing restrictions.
— Apple
AppleMobileFileIntegrity. A downgrade issue was addressed with additional code-signing restrictions.
— Apple
Credit
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2024-27826
- CVE-2024-27804
- CVE-2024-27837
- CVE-2024-27816
- CVE-2024-27825
- CVE-2024-27829
- CVE-2024-27841
- CVE-2024-23236
- CVE-2024-27805
- CVE-2024-27817
- CVE-2024-27831
- CVE-2024-27832
- CVE-2024-27827
- CVE-2024-27801
- CVE-2024-27836
- CVE-2024-27799
- CVE-2024-27818
- CVE-2024-27815
- CVE-2024-27823
- CVE-2024-27811
- CVE-2023-42893
- CVE-2024-23251
- CVE-2024-23282
- CVE-2024-27810
- CVE-2024-27800
- CVE-2024-27802
- CVE-2024-27857
- CVE-2024-27822
- CVE-2024-27824
- CVE-2024-27885
- CVE-2024-27813
- CVE-2024-27844
- CVE-2024-27843
- CVE-2024-27821
- CVE-2024-27855
- CVE-2024-27806
- CVE-2024-27798
- CVE-2024-27848
- CVE-2024-27847
- CVE-2024-27884
- CVE-2024-27842
- CVE-2024-27796
- CVE-2024-27834
- CVE-2024-27838
- CVE-2024-27808
- CVE-2024-27850
- CVE-2024-27851
- CVE-2024-27830
- CVE-2024-27820
- CVE-2024-27828
- CVE-2024-27840
- CVE-2024-27833
- CVE-2024-40771
- CVE-2024-27856
- CVE-2024-27814
- CVE-2024-40799
- CVE-2023-6277
- CVE-2023-52356
- CVE-2024-40806
- CVE-2024-40777
- CVE-2024-40784
- CVE-2024-27863
- CVE-2024-40788
- CVE-2024-40809
- CVE-2024-40812
- CVE-2024-40776
- CVE-2024-40782
- CVE-2024-40779
- CVE-2024-40780
- CVE-2024-40785
- CVE-2024-40789
- CVE-2024-23229
- CVE-2024-27789
- CVE-2023-42861
- CVE-2024-23296
- CVE-2024-44136
- CVE-2024-27839
- CVE-2024-27852
- CVE-2024-27835
- CVE-2024-27845
- CVE-2024-27803
- CVE-2024-27819
- CVE-2024-40839
- CVE-2024-27807
- CVE-2024-54564
- CVE-2024-40865
- CVE-2024-54551
- CVE-2024-44185
- CVE-2024-44206
Frequently Asked Questions
What is the severity of CVE-2024-27823?
CVE-2024-27823 is classified as a vulnerability that can potentially allow an attacker in a privileged network position to exploit a race condition.
How do I fix CVE-2024-27823?
To fix CVE-2024-27823, upgrade to the latest versions of affected operating systems such as macOS Sonoma 14.5, iOS 17.5, or iPadOS 17.5.
Which Apple products are affected by CVE-2024-27823?
CVE-2024-27823 affects several Apple products including macOS Monterey, watchOS, iOS, iPadOS, visionOS, and tvOS.
Is there a workaround for CVE-2024-27823?
There are no known workarounds for CVE-2024-27823 other than applying the necessary software updates.
What types of attacks can CVE-2024-27823 facilitate?
CVE-2024-27823 could potentially facilitate attacks that exploit the race condition to gain unauthorized access in a privileged network.