CVE-2024-44236: Input Validation
An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in macOS Sequoia 15.1, macOS Sonoma 14.7.1, macOS Ventura 13.7.1. Processing a maliciously crafted file may lead to unexpected app termination.
Other sources
Apache. This is a vulnerability in open source code and Apple Software among the affected projects. The CVE-ID was assigned by a third party. Learn more about the issue and CVE-ID at cve.org.
— Apple
App Support. A path handling issue was addressed with improved logic.
— Apple
AppleAVD. The issue was addressed with improved bounds checks.
— Apple
AppleMobileFileIntegrity. A downgrade issue affecting Intel-based Mac computers was addressed with additional code-signing restrictions.
— Apple
AppleMobileFileIntegrity. A logic issue was addressed with improved validation.
— Apple
Credit
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2024-44255
- CVE-2024-44232
- CVE-2024-44233
- CVE-2024-44234
- CVE-2024-44270
- CVE-2024-44280
- CVE-2024-44260
- CVE-2024-44273
- CVE-2024-44295
- CVE-2024-44240
- CVE-2024-44302
- CVE-2024-44213
- CVE-2024-40855
- CVE-2024-44289
- CVE-2024-44282
- CVE-2024-44265
- CVE-2024-40854
- CVE-2024-44215
- CVE-2024-44297
- CVE-2024-44216
- CVE-2024-44287
- CVE-2024-44197
- CVE-2024-44239
- CVE-2024-44175
- CVE-2024-44122
- CVE-2024-44222
- CVE-2024-44256
- CVE-2024-54471
- CVE-2024-44159
- CVE-2024-44156
- CVE-2024-44196
- CVE-2024-44253
- CVE-2024-44247
- CVE-2024-44267
- CVE-2024-44301
- CVE-2024-44275
- CVE-2024-44294
- CVE-2024-44144
- CVE-2024-44218
- CVE-2024-44137
- CVE-2024-54538
- CVE-2024-44254
- CVE-2024-44269
- CVE-2024-44236
- CVE-2024-44237
- CVE-2024-44284
- CVE-2024-44279
- CVE-2024-44281
- CVE-2024-44283
- CVE-2024-44278
- CVE-2024-44264
- CVE-2024-44257
- CVE-2024-44126
- CVE-2024-39573
- CVE-2024-38477
- CVE-2024-38476
- CVE-2024-54535
- CVE-2024-44298
- CVE-2024-54554
- CVE-2024-44299
- CVE-2024-44241
- CVE-2024-44242
- CVE-2024-44238
- CVE-2024-44285
- CVE-2024-44286
- CVE-2024-40849
- CVE-2024-44201
- CVE-2024-44231
- CVE-2024-44223
- CVE-2024-44292
- CVE-2024-44293
- CVE-2024-44303
- CVE-2024-40858
- CVE-2024-44277
- CVE-2024-44195
- CVE-2024-44259
- CVE-2024-44229
- CVE-2024-44219
- CVE-2024-44211
- CVE-2024-44248
- CVE-2024-44194
- CVE-2024-44200
- CVE-2024-44210
- CVE-2024-44290
- CVE-2024-44296
- CVE-2024-44212
- CVE-2024-44244
- CVE-2024-44250
Frequently Asked Questions
What is the severity of CVE-2024-44236?
CVE-2024-44236 is classified as a critical vulnerability due to the potential for unexpected application termination from processing malicious files.
How do I fix CVE-2024-44236?
To remediate CVE-2024-44236, update to macOS Ventura 13.7.1, macOS Sonoma 14.7.1, or macOS Sequoia 15.1.
What are the affected versions of macOS for CVE-2024-44236?
CVE-2024-44236 affects macOS versions prior to 13.7.1 and between 14.0 and 14.7.1.
What type of vulnerability is CVE-2024-44236?
CVE-2024-44236 is an out-of-bounds access vulnerability that can lead to application crashes.
Who is affected by CVE-2024-44236?
Users of specific versions of Apple macOS software are affected by CVE-2024-44236, particularly those on versions before the fixed updates.