CVE-2024-27827: Path Traversal
Published May 13, 2024
·Updated
Apple Neural Engine. The issue was addressed with improved memory handling.
Credit
an anonymous researcher, Kirin@@Pwnrin, 小来来@@Smi1eSEC, pattern-f@@pattern_F_(Ant Security Light), Amir Bazine(CrowdStrike Counter Adversary Operations), Karsten König(CrowdStrike Counter Adversary Operations), Mickey Jin@@patch1t, Pr(Bar), Pr(Hebrew University), EP, an anonymous researcher(Concentrix), 凯 王(Concentrix), Steven Maser(Concentrix), Matthew McLean(Concentrix), Brandon Chesser(Concentrix), CPU IT inc(Concentrix), (Concentrix), Avalon IT Team(Concentrix), LFY@@secsys(Fudan University), Daniel Zajork, Joshua Zajork, Meysam Firouzi@@R00tkitsmm(Trend Micro Zero Day Initiative), Pedro Tôrres@@t0rr3sp3dr0, CVE-2024-23296, CVE-2024-27806, Yann GASCUEL(Alter Solutions), ajajfxhj, Ron Masas(Imperva), CertiK SkyFall Team, Junsung Lee(Trend Micro Zero Day Initiative), an anonymous researcher(MIT CSAIL), (MIT CSAIL), Joseph Ravichandran@@0xjprx(MIT CSAIL), Nick Wellnhofer, Gil Pedersen, Dohyun Lee@@l33d0hyun, Michael DePlante@@izobashi(Trend Micro Zero Day Initiative), Scott Johnson(RIPEDA Consulting), Mykola Grymalyuk(RIPEDA Consulting), Jordy Witteman, Carlos Polop, Narendra Bhati(Suma Soft Pvt), Shaheen Fazim, Csaba Fitzl@@theevilbit(Kandji), LFY@@secsys, yulige, Snoolie Keffaber@@0xilis, Robert Reichel, Maksymilian Motyl(Immunity Systems), Manfred Paul@@_manfp(Trend Micro's Zero Day Initiative), Emilio Cobos(Mozilla), Lukas Bernhard(CISPA Helmholtz Center for Information Security), Nan Wang@@eternalsakura13(360 Vulnerability Research Institute), Joe Rutkowski@@Joe12387(Crawless), @@abrahamjuliot, Jeff Johnson(underpassapp), Pwn2car(Trend Micro's Zero Day Initiative), (Trend Micro's Zero Day Initiative), Michael DePlante@@izobashi(Trend Micro's Zero Day Initiative), Minghao Lin(Baidu Security), (Baidu Security), Ye Zhang@@VAR10CK(Baidu Security), Meysam Firouzi@@R00tkitSMM
Affected Software
4 affected componentsFixes available
Apple macOS<14.5
14.5
macOS Ventura<13.6.7
13.6.7
macOS>=13.0<13.6.7
macOS>=14.0<14.5
Event History
May 13, 2024
Data Sourced
via Apple·12:00 AM
DescriptionWeaknessAffected Software
Updated
via Apple·12:00 AM
DescriptionWeakness
Updated
via Apple·12:00 AM
DescriptionWeaknessAffected Software
CVE Published
via MITRE·11:00 PM
Data Sourced
via MITRE·11:00 PM
DescriptionWeakness
May 14, 2024
Data Sourced
via NVD·03:13 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-27827?
CVE-2024-27827 has a moderate severity level as it allows an app to read arbitrary files.
2
How do I fix CVE-2024-27827?
To fix CVE-2024-27827, update your system to macOS Sonoma 14.5 or macOS Ventura 13.6.7.
3
Which versions of macOS are affected by CVE-2024-27827?
CVE-2024-27827 affects macOS versions prior to 14.5 and 13.6.7.
4
What does CVE-2024-27827 affect specifically?
CVE-2024-27827 affects Finder, allowing unauthorized file access.
5
When was CVE-2024-27827 reported?
CVE-2024-27827 was reported and addressed in 2024.