CVE-2024-40855: Input Validation
Published Sep 16, 2024
·Updated
Accounts. A permissions issue was addressed with additional restrictions.
Credit
an anonymous researcher, Hossein Lotfi@@hosselot(Trend Micro Zero Day Initiative), Alexandre Bedard, Csaba Fitzl@@theevilbit(Kandji), Kirin@@Pwnrin, Ronny Stiftel, Wang Yu(Cyberserval), Junsung Lee(Trend Micro Zero Day Initiative), Jex Amro, Zhongquan Li@@Guluisacat, Mickey Jin@@patch1t, Mateusz Krzywicki@@krzywix, Noah Gregory (wts.dev), Arsenii Kostromin (0x3c3e), Mickey Jin@@patch1t(Kandji), Un3xploitable(CW Research Inc), Bohdan Stasiuk@@Bohdan_Stasiuk(CW Research Inc), Pedro Tôrres@@t0rr3sp3dr0, 냥냥, Michael DePlante@@izobashi(Trend Micro Zero Day Initiative), Halle Winkler, Politepix@@hallewinkler, Bing Shi(Alibaba Group), Wenchao Li(Alibaba Group), Xiaolong Bai(Alibaba Group), (Indiana University Bloomington), Luyi Xing(Indiana University Bloomington), dw0r!(Trend Micro Zero Day Initiative), Bohdan Stasiuk@@Bohdan_Stasiuk, pattern-f@@pattern_F_(Loadshine Lab), Hikerell(Loadshine Lab), Ivan Fratric(Google Project Zero), Holger Fuhrmannek, Rodolphe Brunetti@@eisw0lf, CVE-2023-4504, @@08Tc3wBB(Jamf), Denis Tokarev@@illusionofcha0s, Yiğit Can YILMAZ@@yilmazcanyigit, Junsung Lee, dw0r(ZeroPointer Lab working with Trend Micro Zero Day Initiative), Antonio Zekić, Andrew Lytvynov, Alexander Heinrich, SEEMOO, DistriNet, KU Leuven@@vanhoefm, TU Darmstadt@@Sn0wfreeze, Mathy Vanhoef, Jeff Johnson (underpassapp.com), OSS-Fuzz(Google Project Zero), Ned Williamson(Google Project Zero), Rodolphe BRUNETTI@@eisw0lf, Kirin@@Pwnrin(Fudan University), LFY@@secsys(Fudan University), Olivier Levon, CVE-2023-5841, Meng Zhang (鲸落)(NorthSea), ajajfxhj, Brian McNulty(Computer Science), Cristian Dinca(Computer Science), Romania, Vaibhav Prajapati, CVE-2024-39894, Wojciech Regula(SecuRing), Rifa'i Rejal Maynando, Narendra Bhati(Cyber Security at Suma Soft Pvt), Manager(Cyber Security at Suma Soft Pvt), Pune (India), Yiğit Can YILMAZ@@yilmazcanyigit(SecuRing), Kirin@@Pwnrin(NorthSea), Vivek Dhar, working as Assistant Sub-Inspector (RM) in Border Security Force (Frontier Headquarter BSF Kashmir), Pedro José Pereira Vieito@@pvieito, luckyu@@uuulucky(NorthSea), Om Kothawade(the UNTHSC College of Pharmacy), Omar A. Alanis(the UNTHSC College of Pharmacy), Bistrit Dahal, Matej Moravec@@MacejkoMoravec, K宝, LFY@@secsys, Smi1e, yulige, Cristian Dinca (icmd.tech), Ron Masas(BreakPoint), Jonathan Bar Or@@yo_yo_yo_jbo(Microsoft), CVE-2024-41957, Narendra Bhati(Cyber Security At Suma Soft Pvt), Manager(Cyber Security At Suma Soft Pvt), Tashita Software Security, Ron Masas, Hafiizh(HakTrak), YoKo Kho@@yokoacc(HakTrak), Tim Michaud@@TimGMichaud(Moveworks), Antonio Zekic@@antoniozekic, ant4g0nist, Charly Suchanek, CVE-2024-44134, Preet Dsouza (Fleming College, Computer Security & Investigations Program), Domien Schepers, Tim Clem, Gergely Kalman@@gergely_kalman, Koh M. Nakagawa@@tsunek0h, Snoolie Keffaber@@0xilis, Max Thomas, CVE-2024-44130, Pwn2car(Trend Micro Zero Day Initiative), Claudio Bozzato(Cisco Talos), Francesco Benvenuto(Cisco Talos), Anton Boegler, CVE-2024-44129
Affected Software
6 affected componentsFixes available
apple macOS Sonoma<14.7.1
14.7.1
Apple visionOS<2
2
apple macOS Sequoia<15
15
Apple macOS<13.7.1
Apple macOS>=14.0<14.7.1
apple macOS Ventura<13.7.1
13.7.1
Event History
Sep 16, 2024
Data Sourced
via Apple·12:00 AM
DescriptionWeaknessAffected Software
Updated
via Apple·12:00 AM
DescriptionWeakness
Oct 28, 2024
Updated
via Apple·12:00 AM
DescriptionWeaknessAffected Software
CVE Published
via MITRE·09:08 PM
Data Sourced
via MITRE·09:08 PM
DescriptionWeakness
Data Sourced
via NVD·09:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-40855?
CVE-2024-40855 has a high severity rating due to its permissions issue that could allow unauthorized access.
2
How do I fix CVE-2024-40855?
To fix CVE-2024-40855, update your macOS to version 13.7.1, 14.7.1, or 15.
3
What systems are affected by CVE-2024-40855?
CVE-2024-40855 affects macOS Ventura up to 13.7.1, macOS Sonoma up to 14.7.1, and macOS Sequoia up to 15.
4
What type of vulnerability is CVE-2024-40855?
CVE-2024-40855 is a permissions issue that was addressed with improved checks and restrictions.
5
Is there a workaround for CVE-2024-40855?
There is no reported workaround for CVE-2024-40855; updating your macOS is recommended for mitigation.