CVE-2024-40865: Input Validation
AirDrop. This issue was addressed through improved state management.
Other sources
Apple Neural Engine. The issue was addressed with improved memory handling.
— Apple
AppleAVD. The issue was addressed with improved memory handling.
— Apple
CoreGraphics. An out-of-bounds read issue was addressed with improved input validation.
— Apple
ImageIO. An integer overflow was addressed with improved input validation.
— Apple
ImageIO. An out-of-bounds access issue was addressed with improved bounds checking.
— Apple
Credit
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2024-54564
- CVE-2024-27826
- CVE-2024-27804
- CVE-2024-40799
- CVE-2023-6277
- CVE-2023-52356
- CVE-2024-40806
- CVE-2024-40777
- CVE-2024-40784
- CVE-2024-27863
- CVE-2024-27823
- CVE-2024-40788
- CVE-2024-40865
- CVE-2024-40809
- CVE-2024-40812
- CVE-2024-54551
- CVE-2024-40776
- CVE-2024-40782
- CVE-2024-40779
- CVE-2024-40780
- CVE-2024-40785
- CVE-2024-40789
- CVE-2024-44185
- CVE-2024-44206
Frequently Asked Questions
What is the severity of CVE-2024-40865?
CVE-2024-40865 has been classified with a moderate severity level due to potential data exposure through the virtual keyboard.
How do I fix CVE-2024-40865?
To fix CVE-2024-40865, upgrade to visionOS 1.3 or later where this issue has been addressed.
What software is affected by CVE-2024-40865?
CVE-2024-40865 affects Apple visionOS versions prior to 1.3.
When was CVE-2024-40865 published?
CVE-2024-40865 was published in October 2024.
What type of issue does CVE-2024-40865 represent?
CVE-2024-40865 represents an information disclosure vulnerability related to input handling in the virtual keyboard.