CVE-2024-27841
Published May 13, 2024
·Updated
Apple Neural Engine. The issue was addressed with improved memory handling.
Credit
an anonymous researcher, Minghao Lin(Baidu Security), (Baidu Security), Ye Zhang@@VAR10CK(Baidu Security), Meysam Firouzi@@R00tkitSMM, Mickey Jin@@patch1t, Kirin@@Pwnrin, 小来来@@Smi1eSEC, pattern-f@@pattern_F_(Ant Security Light), Amir Bazine(CrowdStrike Counter Adversary Operations), Karsten König(CrowdStrike Counter Adversary Operations), Lucas Monteiro, Daniel Monteiro, Felipe Monteiro, Alexander Heinrich, SEEMOO, TU Darmstadt@@Sn0wfreeze, Shai Mishali@@freak4pc, CertiK SkyFall Team, Junsung Lee(Trend Micro Zero Day Initiative), Pan ZhenPeng@@Peterpan0927(STAR Labs SG Pte), an anonymous researcher(MIT CSAIL), (MIT CSAIL), Joseph Ravichandran@@0xjprx(MIT CSAIL), Pr(Bar), Pr(Hebrew University), EP, Nick Wellnhofer, Gil Pedersen, Dohyun Lee@@l33d0hyun, LFY@@secsys(Fudan University), Talal Haj Bakry(Mysk Inc), Tommy Mysk@@mysk_co(Mysk Inc), Daniel Zajork, Joshua Zajork, Meysam Firouzi@@R00tkitsmm(Trend Micro Zero Day Initiative), Michael DePlante@@izobashi(Trend Micro Zero Day Initiative), Andr.Ess, Adam Berry, Csaba Fitzl@@theevilbit(Kandji), LFY@@secsys, yulige, Snoolie Keffaber@@0xilis, Robert Reichel, Srijan Poudel, CVE-2024-27806, Abhay Kailasia@@abhay_kailasia(Lakshmi Narain College of Technology Bhopal), Romy R., ajajfxhj, Maksymilian Motyl(Immunity Systems), Manfred Paul@@_manfp(Trend Micro's Zero Day Initiative), Emilio Cobos(Mozilla), Lukas Bernhard(CISPA Helmholtz Center for Information Security), Manfred Paul@@_manfp(Trend Micro Zero Day Initiative), Nan Wang@@eternalsakura13(360 Vulnerability Research Institute), Joe Rutkowski@@Joe12387(Crawless), @@abrahamjuliot, Jeff Johnson(underpassapp), Ron Masas(Imperva), Scott Johnson(RIPEDA Consulting), Mykola Grymalyuk(RIPEDA Consulting), Jordy Witteman, Carlos Polop, Pedro Tôrres@@t0rr3sp3dr0, Narendra Bhati(Suma Soft Pvt), Shaheen Fazim, Yann GASCUEL(Alter Solutions), Pwn2car(Trend Micro's Zero Day Initiative), (Trend Micro's Zero Day Initiative), Michael DePlante@@izobashi(Trend Micro's Zero Day Initiative)
Affected Software
6 affected componentsFixes available
Apple macOS<14.5
14.5
Apple iOS and iPadOS<17.5
17.5
Apple iOS, iPadOS, and macOS<17.5
17.5
Apple iOS, iPadOS, and macOS<17.5
iPhone OS<17.5
macOS>=14.0<14.5
Event History
May 13, 2024
Data Sourced
via Apple·12:00 AM
DescriptionWeaknessAffected Software
Updated
via Apple·12:00 AM
DescriptionWeakness
CVE Published
via MITRE·11:00 PM
Data Sourced
via MITRE·11:00 PM
DescriptionWeakness
May 14, 2024
Data Sourced
via NVD·03:13 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-27841?
CVE-2024-27841 has been categorized with a severity rating indicating a serious risk that may compromise system integrity.
2
How do I fix CVE-2024-27841?
To resolve CVE-2024-27841, users should update to the latest versions of iOS, iPadOS, or macOS as specified in the vendor's remediation.
3
What are the affected versions for CVE-2024-27841?
CVE-2024-27841 affects Apple iOS and iPadOS earlier than version 17.5, and macOS versions from 14.0 to 14.5.
4
What type of issue is CVE-2024-27841?
CVE-2024-27841 is associated with memory handling and code-signing restrictions that have been improved to enhance security.
5
Is CVE-2024-27841 specific to certain Apple devices?
Yes, CVE-2024-27841 affects a range of Intel-based Mac computers, iPhones, and iPads running the vulnerable versions.