CVE-2024-27837
Published May 13, 2024
·Updated
A downgrade issue was addressed with additional code-signing restrictions. This issue is fixed in macOS Sonoma 14.5. A local attacker may gain access to Keychain items.
Credit
Mickey Jin@@patch1t, ajajfxhj, Minghao Lin(Baidu Security), (Baidu Security), Ye Zhang@@VAR10CK(Baidu Security), Meysam Firouzi@@R00tkitSMM, Kirin@@Pwnrin, Amir Bazine(CrowdStrike Counter Adversary Operations), Karsten König(CrowdStrike Counter Adversary Operations), Pwn2car(Trend Micro's Zero Day Initiative), (Trend Micro's Zero Day Initiative), Michael DePlante@@izobashi(Trend Micro's Zero Day Initiative), an anonymous researcher, Ron Masas(Imperva), 小来来@@Smi1eSEC, pattern-f@@pattern_F_(Ant Security Light), CertiK SkyFall Team, Junsung Lee(Trend Micro Zero Day Initiative), an anonymous researcher(MIT CSAIL), (MIT CSAIL), Joseph Ravichandran@@0xjprx(MIT CSAIL), Pr(Bar), Pr(Hebrew University), EP, Nick Wellnhofer, Gil Pedersen, Dohyun Lee@@l33d0hyun, LFY@@secsys(Fudan University), Daniel Zajork, Joshua Zajork, Meysam Firouzi@@R00tkitsmm(Trend Micro Zero Day Initiative), Michael DePlante@@izobashi(Trend Micro Zero Day Initiative), Scott Johnson(RIPEDA Consulting), Mykola Grymalyuk(RIPEDA Consulting), Jordy Witteman, Carlos Polop, Pedro Tôrres@@t0rr3sp3dr0, Narendra Bhati(Suma Soft Pvt), Shaheen Fazim, Csaba Fitzl@@theevilbit(Kandji), LFY@@secsys, yulige, Snoolie Keffaber@@0xilis, Robert Reichel, CVE-2024-27806, Yann GASCUEL(Alter Solutions), Maksymilian Motyl(Immunity Systems), Manfred Paul@@_manfp(Trend Micro's Zero Day Initiative), Emilio Cobos(Mozilla), Lukas Bernhard(CISPA Helmholtz Center for Information Security), Nan Wang@@eternalsakura13(360 Vulnerability Research Institute), Joe Rutkowski@@Joe12387(Crawless), @@abrahamjuliot, Jeff Johnson(underpassapp)
Affected Software
2 affected componentsFixes available
Apple macOS<14.5
14.5
macOS>=14.0<14.5
Event History
May 13, 2024
Data Sourced
via Apple·12:00 AM
DescriptionWeaknessAffected Software
Updated
via Apple·12:00 AM
DescriptionWeakness
CVE Published
via MITRE·11:00 PM
Data Sourced
via MITRE·11:00 PM
DescriptionWeakness
May 14, 2024
Data Sourced
via NVD·03:13 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-27837?
CVE-2024-27837 has been rated as high severity due to its potential impact on Keychain item access.
2
How do I fix CVE-2024-27837?
To fix CVE-2024-27837, update your macOS to version 14.5 or later.
3
Who is affected by CVE-2024-27837?
CVE-2024-27837 affects users running macOS versions from 14.0 up to but not including 14.5.
4
What components are involved in CVE-2024-27837?
CVE-2024-27837 involves issues with code-signing restrictions and memory handling in macOS.
5
What potential risks does CVE-2024-27837 pose?
CVE-2024-27837 poses a risk of unauthorized access to sensitive data stored in the Keychain.