CVE-2024-27845: Input Validation
A privacy issue was addressed with improved handling of temporary files. This issue is fixed in iOS 17.5 and iPadOS 17.5. An app may be able to access Notes attachments.
Other sources
Apple Neural Engine. The issue was addressed with improved memory handling.
— Apple
AppleAVD. The issue was addressed with improved memory handling.
— Apple
AVEVideoEncoder. The issue was addressed with improved memory handling.
— Apple
Core Data. An issue was addressed with improved validation of environment variables.
— Apple
CoreMedia. An out-of-bounds write issue was addressed with improved input validation.
— Apple
Credit
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2024-27826
- CVE-2024-27804
- CVE-2024-27816
- CVE-2024-40771
- CVE-2024-27841
- CVE-2024-27805
- CVE-2024-27817
- CVE-2024-27831
- CVE-2024-27832
- CVE-2024-44136
- CVE-2024-27839
- CVE-2024-27801
- CVE-2024-27836
- CVE-2024-27828
- CVE-2024-27818
- CVE-2024-27840
- CVE-2024-27815
- CVE-2024-27823
- CVE-2024-27811
- CVE-2023-42893
- CVE-2024-23251
- CVE-2024-23282
- CVE-2024-27810
- CVE-2024-27852
- CVE-2024-27800
- CVE-2024-27802
- CVE-2024-27857
- CVE-2024-27835
- CVE-2024-27845
- CVE-2024-27803
- CVE-2024-27821
- CVE-2024-27855
- CVE-2024-27819
- CVE-2024-27806
- CVE-2024-40839
- CVE-2024-27848
- CVE-2024-27807
- CVE-2024-27847
- CVE-2024-27884
- CVE-2024-27796
- CVE-2024-27856
- CVE-2024-27834
- CVE-2024-27838
- CVE-2024-27808
- CVE-2024-27850
- CVE-2024-27833
- CVE-2024-27851
- CVE-2024-27830
- CVE-2024-27820
Frequently Asked Questions
What is the severity of CVE-2024-27845?
CVE-2024-27845 is categorized as a privacy issue that could potentially lead to unauthorized access to Notes attachments.
How do I fix CVE-2024-27845?
To fix CVE-2024-27845, update your Apple device to iOS 17.5 or iPadOS 17.5.
What devices are affected by CVE-2024-27845?
CVE-2024-27845 affects devices running iOS versions prior to 17.5 and iPadOS versions prior to 17.5.
Is data compromised due to CVE-2024-27845?
Yes, CVE-2024-27845 may allow apps to access sensitive Notes attachments, leading to potential privacy violations.
When was CVE-2024-27845 disclosed?
CVE-2024-27845 was disclosed as part of Apple's ongoing security updates and addressed in the 17.5 release.