CVE-2024-40867: Input Validation
A custom URL scheme handling issue was addressed with improved input validation. This issue is fixed in iOS 18.1 and iPadOS 18.1. A remote attacker may be able to break out of Web Content sandbox.
Other sources
Accessibility. The issue was addressed with improved authentication.
— Apple
App Support. A path handling issue was addressed with improved logic.
— Apple
AppleAVD. The issue was addressed with improved bounds checks.
— Apple
Calendar. A path handling issue was addressed with improved logic.
— Apple
CoreMedia Playback. This issue was addressed with improved handling of symlinks.
— Apple
Credit
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2024-44274
- CVE-2024-44255
- CVE-2024-44232
- CVE-2024-44233
- CVE-2024-44234
- CVE-2024-54535
- CVE-2024-44273
- CVE-2024-44240
- CVE-2024-44302
- CVE-2024-44282
- CVE-2024-40854
- CVE-2024-44215
- CVE-2024-44297
- CVE-2024-44299
- CVE-2024-44241
- CVE-2024-44242
- CVE-2024-44238
- CVE-2024-44285
- CVE-2024-40867
- CVE-2024-44239
- CVE-2024-44201
- CVE-2024-44258
- CVE-2024-44252
- CVE-2024-44277
- CVE-2024-44259
- CVE-2024-44229
- CVE-2024-44218
- CVE-2024-54538
- CVE-2024-44254
- CVE-2024-44269
- CVE-2024-54470
- CVE-2024-44194
- CVE-2024-40851
- CVE-2024-44263
- CVE-2024-44278
- CVE-2024-44200
- CVE-2024-44251
- CVE-2024-44235
- CVE-2024-44261
- CVE-2024-44290
- CVE-2024-44212
- CVE-2024-44296
- CVE-2024-44244
- CVE-2024-54556
Frequently Asked Questions
What is the severity of CVE-2024-40867?
CVE-2024-40867 is considered a significant vulnerability due to its potential to allow remote attackers to escape the Web Content sandbox.
How do I fix CVE-2024-40867?
To mitigate CVE-2024-40867, update your device to iOS 18.1 or iPadOS 18.1, which address the vulnerability through improved input validation.
Which devices are affected by CVE-2024-40867?
CVE-2024-40867 affects devices running iOS versions prior to 18.1 and iPadOS versions prior to 18.1.
Can CVE-2024-40867 be exploited remotely?
Yes, a remote attacker may exploit CVE-2024-40867 to break out of the Web Content sandbox if no updates are applied.
What type of issue is CVE-2024-40867?
CVE-2024-40867 is a custom URL scheme handling issue that was addressed with improved authentication measures.