CVE-2024-44190: Path Traversal
A path handling issue was addressed with improved validation. This issue is fixed in macOS Sequoia 15, macOS Sonoma 14.7, macOS Ventura 13.7. An app may be able to read arbitrary files.
Other sources
Accounts. A permissions issue was addressed with additional restrictions.
— Apple
Accounts. The issue was addressed with improved checks.
— Apple
Accounts. The issue was addressed with improved permissions logic.
— Apple
Airport. A permissions issue was addressed with additional restrictions.
— Apple
APFS. The issue was addressed with improved checks.
— Apple
Credit
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2024-44153
- CVE-2024-44182
- CVE-2024-40846
- CVE-2024-40845
- CVE-2024-44154
- CVE-2024-40847
- CVE-2024-44164
- CVE-2024-44168
- CVE-2024-40848
- CVE-2024-40841
- CVE-2024-44135
- CVE-2024-44126
- CVE-2024-44128
- CVE-2024-44151
- CVE-2024-27876
- CVE-2024-44177
- CVE-2024-54469
- CVE-2024-40850
- CVE-2024-27880
- CVE-2024-44176
- CVE-2024-44160
- CVE-2024-44161
- CVE-2024-44169
- CVE-2024-44165
- CVE-2024-40791
- CVE-2024-44181
- CVE-2024-44183
- CVE-2024-44167
- CVE-2024-44178
- CVE-2024-40797
- CVE-2024-44163
- CVE-2024-44125
- CVE-2024-40801
- CVE-2024-44158
- CVE-2024-40844
- CVE-2024-40860
- CVE-2024-44166
- CVE-2024-44190
- CVE-2024-44184
- CVE-2024-44129
- CVE-2024-27886
- CVE-2024-40814
- CVE-2024-44188
- CVE-2024-40792
- CVE-2024-40825
- CVE-2024-44130
- CVE-2024-40837
- CVE-2024-27860
- CVE-2024-27861
- CVE-2024-27795
- CVE-2024-44132
- CVE-2024-44172
- CVE-2024-27869
- CVE-2024-27875
- CVE-2024-44146
- CVE-2024-27849
- CVE-2023-4504
- CVE-2024-40855
- CVE-2024-44148
- CVE-2024-44131
- CVE-2024-54463
- CVE-2024-40831
- CVE-2024-40861
- CVE-2024-44175
- CVE-2024-44191
- CVE-2024-54560
- CVE-2024-44122
- CVE-2024-44198
- CVE-2024-54473
- CVE-2023-5841
- CVE-2024-27858
- CVE-2024-40838
- CVE-2024-44186
- CVE-2024-39894
- CVE-2024-40826
- CVE-2024-44149
- CVE-2024-44155
- CVE-2024-44203
- CVE-2024-44144
- CVE-2024-44137
- CVE-2024-44174
- CVE-2024-44123
- CVE-2024-44145
- CVE-2024-44179
- CVE-2024-44170
- CVE-2024-44152
- CVE-2024-54558
- CVE-2024-44133
- CVE-2024-40859
- CVE-2024-41957
- CVE-2024-54467
- CVE-2024-44192
- CVE-2024-40857
- CVE-2024-40866
- CVE-2024-44187
- CVE-2024-44227
- CVE-2024-54546
- CVE-2024-40770
- CVE-2024-23237
- CVE-2024-44134
- CVE-2024-40856
- CVE-2024-44189
- CVE-2024-44208
- CVE-2024-40842
- CVE-2024-40843
Frequently Asked Questions
What is the severity of CVE-2024-44190?
CVE-2024-44190 has been rated as a medium severity vulnerability due to its potential for unauthorized file access.
How do I fix CVE-2024-44190?
To fix CVE-2024-44190, update your macOS to version 13.7, 14.7, or 15.
What systems are affected by CVE-2024-44190?
CVE-2024-44190 affects macOS Ventura versions prior to 13.7, macOS Sonoma versions prior to 14.7, and macOS Sequoia versions prior to 15.
What type of issue is CVE-2024-44190?
CVE-2024-44190 is a path handling issue that could allow an app to read arbitrary files.
What are the consequences of CVE-2024-44190?
The consequences of CVE-2024-44190 include potential unauthorized access to sensitive files on affected systems.