CVE-2024-27877
Published Jul 29, 2024
·Updated
Accounts. The issue was addressed with improved checks.
Credit
Michael DePlante@@izobashi(Trend Micro Zero Day Initiative), D4m0n, Amir Bazine(CrowdStrike Counter Adversary Operations), Karsten König(CrowdStrike Counter Adversary Operations), CVE-2024-2004, CVE-2024-2379, CVE-2024-2398, CVE-2024-2466, an anonymous researcher, Mickey Jin@@patch1t, CVE-2023-6277, CVE-2023-52356, Yisumi, sqrtpwn, Minghao Lin(Zhejiang University), Jiaxun Zhu(Zhejiang University), Patrick Wardle(DoubleYou), Adam M., CVE-2024-6387, Zhongquan Li@@Guluisacat(Dawn Security Lab of JingDong), Csaba Fitzl@@theevilbit(Kandji), Claudio Bozzato(Cisco Talos), Francesco Benvenuto(Cisco Talos), CVE-2024-23296, Yadhu Krishna M(Cyber Security At Suma Soft Pvt), Narendra Bhati(Cyber Security At Suma Soft Pvt), Manager(Cyber Security At Suma Soft Pvt), Pune (India), Kirin@@Pwnrin, Joshua Jones, Marcio Almeida(Tanto Security), Jiahui Hu (梅零落)(NorthSea), Meng Zhang (鲸落)(NorthSea), Matthew Loewen, Minghao Lin(Baidu Security), (Baidu Security), Ye Zhang@@VAR10CK(Baidu Security), IES Red Team(ByteDance), Linwz(DEVCORE), Yeto, CertiK SkyFall Team, Yann Gascuel(Alter Solutions), w0wbox, Junsung Lee(Trend Micro Zero Day Initiative), (CrowdStrike Counter Adversary Operations), Gandalf4a, Wang Yu(Cyberserval), CVE-2024-40805, Rodolphe BRUNETTI@@eisw0lf, Pedro Tôrres@@t0rr3sp3dr0, Mickey Jin@@patch1t(Kandji), (Kandji), Mateen Alinaghi, Csaba Fitzl@@theevilbit(Offensive Security), Wojciech Regula(SecuRing), (Dawn Security Lab of JingDong), Jiwon Park, Bistrit Dahal, Srijan Poudel, Arsenii Kostromin (0x3c3e), ajajfxhj, Huang Xilin(Ant Group Light), Maksymilian Motyl, Johan Carlsson (joaxcar), Seunghyun Lee@@0x10n(KAIST Hacking Lab working with Trend Micro Zero Day Initiative), CVE-2024-4558, Matthew Butler, Gary Kwong, Andreas Jaegersberger, Ro Achterberg, Abhay Kailasia@@abhay_kailasia(Lakshmi Narain College of Technology Bhopal India)
Affected Software
6 affected componentsFixes available
apple macOS Sonoma<14.6
14.6
apple macOS Monterey<12.7.6
12.7.6
apple macOS Ventura<13.6.8
13.6.8
Apple macOS>=12.0<12.7.6
Apple macOS>=13<13.6.8
Apple macOS>=14<14.6
Event History
Jul 29, 2024
CVE Published
via MITRE·10:17 PM
Data Sourced
via MITRE·10:17 PM
DescriptionWeakness
Data Sourced
via NVD·11:15 PM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-27877?
CVE-2024-27877 is classified as a potential denial-of-service vulnerability.
2
How do I fix CVE-2024-27877?
To fix CVE-2024-27877, update your system to macOS Sonoma 14.6, macOS Monterey 12.7.6, or macOS Ventura 13.6.8.
3
What are the affected macOS versions for CVE-2024-27877?
CVE-2024-27877 affects macOS versions prior to 12.7.6, 13.6.8, and 14.6.
4
What type of issue is CVE-2024-27877?
CVE-2024-27877 pertains to an issue with memory handling in AppleVA that could lead to denial-of-service.
5
Does CVE-2024-27877 require user action?
Yes, CVE-2024-27877 requires users to update their macOS to mitigate the vulnerability.