CVE-2024-44255: Path Traversal
A path handling issue was addressed with improved logic. This issue is fixed in iOS 18.1 and iPadOS 18.1, macOS Sequoia 15.1, macOS Sonoma 14.7.1, macOS Ventura 13.7.1, tvOS 18.1, visionOS 2.1, watchOS 11.1. A malicious app may be able to run arbitrary shortcuts without user consent.
Other sources
Accessibility. The issue was addressed with improved authentication.
— Apple
Apache. This is a vulnerability in open source code and Apple Software among the affected projects. The CVE-ID was assigned by a third party. Learn more about the issue and CVE-ID at cve.org.
— Apple
App Support. A path handling issue was addressed with improved logic.
— Apple
Credit
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2024-44274
- CVE-2024-44255
- CVE-2024-44232
- CVE-2024-44233
- CVE-2024-44234
- CVE-2024-54535
- CVE-2024-44273
- CVE-2024-44240
- CVE-2024-44302
- CVE-2024-44282
- CVE-2024-44215
- CVE-2024-44297
- CVE-2024-44285
- CVE-2024-44239
- CVE-2024-54538
- CVE-2024-44254
- CVE-2024-44269
- CVE-2024-44194
- CVE-2024-44278
- CVE-2024-44290
- CVE-2024-44212
- CVE-2024-44296
- CVE-2024-44244
- CVE-2024-44270
- CVE-2024-44280
- CVE-2024-44260
- CVE-2024-44295
- CVE-2024-44213
- CVE-2024-40855
- CVE-2024-44289
- CVE-2024-44265
- CVE-2024-40854
- CVE-2024-44216
- CVE-2024-44287
- CVE-2024-44197
- CVE-2024-44175
- CVE-2024-44122
- CVE-2024-44222
- CVE-2024-44256
- CVE-2024-54471
- CVE-2024-44159
- CVE-2024-44156
- CVE-2024-44196
- CVE-2024-44253
- CVE-2024-44247
- CVE-2024-44267
- CVE-2024-44301
- CVE-2024-44275
- CVE-2024-44294
- CVE-2024-44144
- CVE-2024-44218
- CVE-2024-44137
- CVE-2024-44236
- CVE-2024-44237
- CVE-2024-44284
- CVE-2024-44279
- CVE-2024-44281
- CVE-2024-44283
- CVE-2024-44264
- CVE-2024-44257
- CVE-2024-44126
- CVE-2024-44258
- CVE-2024-44252
- CVE-2024-44277
- CVE-2024-44262
- CVE-2024-44259
- CVE-2024-44229
- CVE-2024-44299
- CVE-2024-44241
- CVE-2024-44242
- CVE-2024-44238
- CVE-2024-40867
- CVE-2024-44201
- CVE-2024-54470
- CVE-2024-40851
- CVE-2024-44263
- CVE-2024-44200
- CVE-2024-44251
- CVE-2024-44235
- CVE-2024-44261
- CVE-2024-54556
- CVE-2024-39573
- CVE-2024-38477
- CVE-2024-38476
- CVE-2024-44298
- CVE-2024-54554
- CVE-2024-44286
- CVE-2024-40849
- CVE-2024-44231
- CVE-2024-44223
- CVE-2024-44292
- CVE-2024-44293
- CVE-2024-44303
- CVE-2024-40858
- CVE-2024-44195
- CVE-2024-44219
- CVE-2024-44211
- CVE-2024-44248
- CVE-2024-44210
- CVE-2024-44250
Frequently Asked Questions
What is the severity of CVE-2024-44255?
CVE-2024-44255 is considered a medium severity vulnerability due to the potential for a malicious app to execute shortcuts without user consent.
How do I fix CVE-2024-44255?
To fix CVE-2024-44255, update your device to the latest versions: visionOS 2.1, iOS 18.1, iPadOS 18.1, macOS Ventura 13.7.1, macOS Sonoma 14.7.1, watchOS 11.1, or tvOS 18.1.
What types of devices are affected by CVE-2024-44255?
CVE-2024-44255 affects various Apple devices including iPhones, iPads, Macs, Apple Watches, and Apple TVs running specified versions of their operating systems.
What is the impact of exploiting CVE-2024-44255?
Exploiting CVE-2024-44255 allows a malicious app to run arbitrary shortcuts without the user's consent, potentially leading to unauthorized actions.
Is there a workaround for CVE-2024-44255 if I cannot update?
Currently, there is no recommended workaround for CVE-2024-44255 other than applying the necessary updates provided by Apple.