CVE-2024-27880: Input Validation
Published Sep 16, 2024
·Updated
Accessibility. This issue was addressed by restricting options offered on a locked device.
Credit
Kirin@@Pwnrin, Rodolphe Brunetti@@eisw0lf, CVE-2023-4504, Csaba Fitzl@@theevilbit(Kandji), an anonymous researcher, @@08Tc3wBB(Jamf), Denis Tokarev@@illusionofcha0s, Yiğit Can YILMAZ@@yilmazcanyigit, Mickey Jin@@patch1t, Junsung Lee, dw0r(ZeroPointer Lab working with Trend Micro Zero Day Initiative), Michael DePlante@@izobashi(Trend Micro Zero Day Initiative), Antonio Zekić, Andrew Lytvynov, Alexander Heinrich, SEEMOO, DistriNet, KU Leuven@@vanhoefm, TU Darmstadt@@Sn0wfreeze, Mathy Vanhoef, Jeff Johnson (underpassapp.com), OSS-Fuzz(Google Project Zero), Ned Williamson(Google Project Zero), Rodolphe BRUNETTI@@eisw0lf, Kirin@@Pwnrin(Fudan University), LFY@@secsys(Fudan University), Olivier Levon, CVE-2023-5841, Meng Zhang (鲸落)(NorthSea), ajajfxhj, Brian McNulty(Computer Science), Cristian Dinca(Computer Science), Romania, Vaibhav Prajapati, CVE-2024-39894, Wojciech Regula(SecuRing), Rifa'i Rejal Maynando, Narendra Bhati(Cyber Security at Suma Soft Pvt), Manager(Cyber Security at Suma Soft Pvt), Pune (India), Zhongquan Li@@Guluisacat, Yiğit Can YILMAZ@@yilmazcanyigit(SecuRing), Kirin@@Pwnrin(NorthSea), 냥냥, Halle Winkler, Politepix@@hallewinkler, Vivek Dhar, working as Assistant Sub-Inspector (RM) in Border Security Force (Frontier Headquarter BSF Kashmir), Pedro José Pereira Vieito@@pvieito, luckyu@@uuulucky(NorthSea), Om Kothawade(the UNTHSC College of Pharmacy), Omar A. Alanis(the UNTHSC College of Pharmacy), Bistrit Dahal, Matej Moravec@@MacejkoMoravec, K宝, LFY@@secsys, Smi1e, yulige, Cristian Dinca (icmd.tech), Arsenii Kostromin (0x3c3e), Ron Masas(BreakPoint), Jonathan Bar Or@@yo_yo_yo_jbo(Microsoft), Bohdan Stasiuk@@Bohdan_Stasiuk, CVE-2024-41957, Narendra Bhati(Cyber Security At Suma Soft Pvt), Manager(Cyber Security At Suma Soft Pvt), Tashita Software Security, Ron Masas, Hafiizh(HakTrak), YoKo Kho@@yokoacc(HakTrak), Tim Michaud@@TimGMichaud(Moveworks), Antonio Zekic@@antoniozekic, ant4g0nist, Charly Suchanek, CVE-2024-44134, Preet Dsouza (Fleming College, Computer Security & Investigations Program), Domien Schepers, Tim Clem, Gergely Kalman@@gergely_kalman, Koh M. Nakagawa@@tsunek0h, Snoolie Keffaber@@0xilis, Max Thomas, Claudio Bozzato(Cisco Talos), Francesco Benvenuto(Cisco Talos), Holger Fuhrmannek, Anton Boegler, Pwn2car(Trend Micro Zero Day Initiative), Pedro Tôrres@@t0rr3sp3dr0, CVE-2024-44130, Jake Derouin (jakederouin.com), CVE-2024-44129, Joshua Keller, Lukas, Kenneth Chew, Anamika Adhikari, Om Kothawade(Zaprico Digital), Chi Yuan Chang(ZUSO ART), taikosoup, Srijan Poudel, Justin Cohen, Daniele Antonioli, Tuan D. Hoang, Chloe Surett, Abhay Kailasia@@abhay_kailasia(Lakshmi Narain College of Technology Bhopal India)
Affected Software
15 affected componentsFixes available
Apple macOS Sonoma<14.7
14.7
Apple visionOS<2
2
Apple macOS Sequoia<15
15
Apple tvOS<18
18
Apple WatchOS<11
11
Apple iOS<18
18
Apple iPadOS<18
18
Apple iOS<17.7
17.7
Apple iPadOS<17.7
17.7
Apple iPadOS<17.7
Apple iPhone OS<17.7
Apple macOS<14.7
Apple tvOS<=18.0
Apple visionOS<2.0
Apple WatchOS<11.0
Event History
Sep 16, 2024
Data Sourced
via Apple·12:00 AM
DescriptionWeaknessAffected Software
Updated
via Apple·12:00 AM
DescriptionWeakness
CVE Published
via MITRE·11:22 PM
Data Sourced
via MITRE·11:22 PM
DescriptionWeakness
Sep 17, 2024
Data Sourced
via NVD·12:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-27880?
CVE-2024-27880 is classified as a vulnerability due to its potential for causing unexpected app termination.
2
How do I fix CVE-2024-27880?
To fix CVE-2024-27880, update your device to iOS 17.7, iPadOS 17.7, macOS Sequoia 15, tvOS 18, or their respective newer versions.
3
What impact does CVE-2024-27880 have on affected systems?
CVE-2024-27880 may lead to unexpected termination of apps when processing a malicious file.
4
Which versions of Apple software are affected by CVE-2024-27880?
CVE-2024-27880 affects versions of iPadOS, iPhone OS, macOS, tvOS, visionOS, and watchOS up to specified version limits.
5
Is there a way to identify if my system is vulnerable to CVE-2024-27880?
You can identify vulnerability to CVE-2024-27880 by checking if your system is running a vulnerable version of the software mentioned in the CVE description.