CVE-2024-44263: Use After Free
A logic issue was addressed with improved state management. This issue is fixed in iOS 18.1 and iPadOS 18.1. An app may be able to access user-sensitive data.
Other sources
Accessibility. The issue was addressed with improved authentication.
— Apple
App Support. A path handling issue was addressed with improved logic.
— Apple
AppleAVD. The issue was addressed with improved bounds checks.
— Apple
Calendar. A path handling issue was addressed with improved logic.
— Apple
CoreMedia Playback. This issue was addressed with improved handling of symlinks.
— Apple
Credit
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2024-44274
- CVE-2024-44255
- CVE-2024-44232
- CVE-2024-44233
- CVE-2024-44234
- CVE-2024-54535
- CVE-2024-44273
- CVE-2024-44240
- CVE-2024-44302
- CVE-2024-44282
- CVE-2024-40854
- CVE-2024-44215
- CVE-2024-44297
- CVE-2024-44299
- CVE-2024-44241
- CVE-2024-44242
- CVE-2024-44238
- CVE-2024-44285
- CVE-2024-40867
- CVE-2024-44239
- CVE-2024-44201
- CVE-2024-44258
- CVE-2024-44252
- CVE-2024-44277
- CVE-2024-44259
- CVE-2024-44229
- CVE-2024-44218
- CVE-2024-54538
- CVE-2024-44254
- CVE-2024-44269
- CVE-2024-54470
- CVE-2024-44194
- CVE-2024-40851
- CVE-2024-44263
- CVE-2024-44278
- CVE-2024-44200
- CVE-2024-44251
- CVE-2024-44235
- CVE-2024-44261
- CVE-2024-44290
- CVE-2024-44212
- CVE-2024-44296
- CVE-2024-44244
- CVE-2024-54556
Frequently Asked Questions
What is the severity of CVE-2024-44263?
CVE-2024-44263 has been classified with a medium severity level due to the potential for unauthorized access to user-sensitive data.
How do I fix CVE-2024-44263?
To fix CVE-2024-44263, users should update their devices to iOS 18.1 or iPadOS 18.1.
What type of issue is described in CVE-2024-44263?
CVE-2024-44263 describes a logic issue related to state management and authentication vulnerabilities.
Which devices are affected by CVE-2024-44263?
CVE-2024-44263 affects devices running versions before iOS 18.1 and iPadOS 18.1.
What kind of data might be compromised due to CVE-2024-44263?
CVE-2024-44263 may allow an app to access user-sensitive data due to the identified vulnerabilities.