CVE-2024-27834: Input Validation
An attacker with arbitrary read and write capability may be able to bypass Pointer Authentication. Description: The issue was addressed with improved checks. WebKit Bugzilla: 272750 Versions affected: WebKitGTK and WPE WebKit before 2.44.2.
Credit
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-27834?
CVE-2024-27834 has been evaluated as a significant vulnerability allowing potential bypass of Pointer Authentication.
How do I fix CVE-2024-27834?
To fix CVE-2024-27834, upgrade your software to the latest versions such as iOS 17.5, iPadOS 17.5, tvOS 17.5, macOS Sonoma 14.5, Safari 17.5, or the updated versions of WebKitGTK as specified.
Which platforms are affected by CVE-2024-27834?
CVE-2024-27834 affects various platforms including iOS, iPadOS, tvOS, watchOS, macOS, and specific versions of WebKitGTK.
What type of vulnerability is CVE-2024-27834?
CVE-2024-27834 is a vulnerability related to the potential bypass of Pointer Authentication through arbitrary read and write capabilities.
When was CVE-2024-27834 disclosed?
CVE-2024-27834 was disclosed alongside the release of fixes in 2024 for multiple Apple and WebKitGTK products.