CVE-2024-44252: Input Validation
A logic issue was addressed with improved file handling. This issue is fixed in iOS 17.7.1 and iPadOS 17.7.1, iOS 18.1 and iPadOS 18.1, tvOS 18.1, visionOS 2.1. Restoring a maliciously crafted backup file may lead to modification of protected system files.
Other sources
Accessibility. The issue was addressed with improved authentication.
— Apple
App Support. A path handling issue was addressed with improved logic.
— Apple
AppleAVD. The issue was addressed with improved bounds checks.
— Apple
Calendar. A path handling issue was addressed with improved logic.
— Apple
CoreMedia Playback. This issue was addressed with improved handling of symlinks.
— Apple
Credit
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2024-44255
- CVE-2024-44232
- CVE-2024-44233
- CVE-2024-44234
- CVE-2024-44273
- CVE-2024-44240
- CVE-2024-44302
- CVE-2024-44282
- CVE-2024-44215
- CVE-2024-44297
- CVE-2024-44285
- CVE-2024-44239
- CVE-2024-44258
- CVE-2024-44252
- CVE-2024-44277
- CVE-2024-54538
- CVE-2024-44212
- CVE-2024-44296
- CVE-2024-44244
- CVE-2024-54535
- CVE-2024-44262
- CVE-2024-44259
- CVE-2024-44229
- CVE-2024-44269
- CVE-2024-44194
- CVE-2024-44278
- CVE-2024-44274
- CVE-2024-40854
- CVE-2024-44155
- CVE-2024-44144
- CVE-2024-44218
- CVE-2024-54470
- CVE-2024-44261
- CVE-2024-44299
- CVE-2024-44241
- CVE-2024-44242
- CVE-2024-44238
- CVE-2024-40867
- CVE-2024-44201
- CVE-2024-44254
- CVE-2024-40851
- CVE-2024-44263
- CVE-2024-44200
- CVE-2024-44251
- CVE-2024-44235
- CVE-2024-44290
- CVE-2024-54556
Frequently Asked Questions
What is the severity of CVE-2024-44252?
CVE-2024-44252 is classified as a critical vulnerability due to its potential to allow modification of protected system files.
How do I fix CVE-2024-44252?
To fix CVE-2024-44252, update your device to iOS 18.1, iPadOS 18.1, visionOS 2.1, or tvOS 18.1.
What devices are affected by CVE-2024-44252?
CVE-2024-44252 affects devices running iOS versions up to 17.7.1 and those between iOS 18.0 and 18.1.
Can restoring a backup cause CVE-2024-44252?
Yes, restoring a maliciously crafted backup file can trigger CVE-2024-44252, potentially leading to system file modifications.
Is there a workaround for CVE-2024-44252 before updating?
Currently, there are no effective workarounds for CVE-2024-44252, and updating is strongly recommended.