CVE-2024-27885: Input Validation
Apple Neural Engine. The issue was addressed with improved memory handling.
Other sources
AppleAVD. The issue was addressed with improved memory handling.
— Apple
AppleMobileFileIntegrity. A downgrade issue affecting Intel-based Mac computers was addressed with additional code-signing restrictions.
— Apple
AppleMobileFileIntegrity. A downgrade issue was addressed with additional code-signing restrictions.
— Apple
AppleVA. The issue was addressed with improved memory handling.
— Apple
AVEVideoEncoder. The issue was addressed with improved memory handling.
— Apple
Credit
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2024-27826
- CVE-2024-27804
- CVE-2024-27837
- CVE-2024-27816
- CVE-2024-27825
- CVE-2024-27829
- CVE-2024-27841
- CVE-2024-23236
- CVE-2024-27805
- CVE-2024-27817
- CVE-2024-27831
- CVE-2024-27832
- CVE-2024-27827
- CVE-2024-27801
- CVE-2024-27836
- CVE-2024-27799
- CVE-2024-27818
- CVE-2024-27815
- CVE-2024-27823
- CVE-2024-27811
- CVE-2023-42893
- CVE-2024-23251
- CVE-2024-23282
- CVE-2024-27810
- CVE-2024-27800
- CVE-2024-27802
- CVE-2024-27857
- CVE-2024-27822
- CVE-2024-27824
- CVE-2024-27885
- CVE-2024-27813
- CVE-2024-27844
- CVE-2024-27843
- CVE-2024-27821
- CVE-2024-27855
- CVE-2024-27806
- CVE-2024-27798
- CVE-2024-27848
- CVE-2024-27847
- CVE-2024-27884
- CVE-2024-27842
- CVE-2024-27796
- CVE-2024-27834
- CVE-2024-27838
- CVE-2024-27808
- CVE-2024-27850
- CVE-2024-27851
- CVE-2024-27830
- CVE-2024-27820
- CVE-2024-40771
- CVE-2024-23229
- CVE-2024-27789
- CVE-2024-27840
- CVE-2023-42861
- CVE-2024-23296
- CVE-2024-27856
Frequently Asked Questions
What is the severity of CVE-2024-27885?
CVE-2024-27885 has been classified as a moderate severity vulnerability due to its potential to allow applications to modify protected areas of the file system.
How do I fix CVE-2024-27885?
CVE-2024-27885 can be fixed by updating to macOS Sonoma 14.5, macOS Ventura 13.6.7, or macOS Monterey 12.7.5.
What are the affected macOS versions for CVE-2024-27885?
CVE-2024-27885 affects macOS versions up to 12.7.5, 13.0 through 13.6.7, and 14.0 through 14.5.
What does CVE-2024-27885 involve?
CVE-2024-27885 involves improper validation of symlinks that may allow an application to affect protected parts of the file system.
Is there a workaround for CVE-2024-27885?
There is no specific workaround for CVE-2024-27885; the only recommended solution is to update to the patched macOS versions.