CVE-2024-44255: Path Traversal
A path handling issue was addressed with improved logic. This issue is fixed in iOS 18.1 and iPadOS 18.1, macOS Sequoia 15.1, macOS Sonoma 14.7.1, macOS Ventura 13.7.1, tvOS 18.1, visionOS 2.1, watchOS 11.1. A malicious app may be able to run arbitrary shortcuts without user consent.
Credit
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-44255?
CVE-2024-44255 is considered a medium severity vulnerability due to the potential for a malicious app to execute shortcuts without user consent.
How do I fix CVE-2024-44255?
To fix CVE-2024-44255, update your device to the latest versions: visionOS 2.1, iOS 18.1, iPadOS 18.1, macOS Ventura 13.7.1, macOS Sonoma 14.7.1, watchOS 11.1, or tvOS 18.1.
What types of devices are affected by CVE-2024-44255?
CVE-2024-44255 affects various Apple devices including iPhones, iPads, Macs, Apple Watches, and Apple TVs running specified versions of their operating systems.
What is the impact of exploiting CVE-2024-44255?
Exploiting CVE-2024-44255 allows a malicious app to run arbitrary shortcuts without the user's consent, potentially leading to unauthorized actions.
Is there a workaround for CVE-2024-44255 if I cannot update?
Currently, there is no recommended workaround for CVE-2024-44255 other than applying the necessary updates provided by Apple.