CVE-2024-44270
Published Oct 28, 2024
·Updated
A logic issue was addressed with improved validation. This issue is fixed in macOS Sequoia 15.1, macOS Sonoma 14.7.1, macOS Ventura 13.7.1. A sandboxed process may be able to circumvent sandbox restrictions.
Credit
CVE-2024-39573, CVE-2024-38477, CVE-2024-38476, an anonymous researcher, Ivan Fratric(Google Project Zero), Mickey Jin@@patch1t, K宝@@Pwnrin, Kirin@@Pwnrin, 7feilee, pattern-f@@pattern_F_(Loadshine Lab), Hikerell(Loadshine Lab), Hossein Lotfi@@hosselot(Trend Micro Zero Day Initiative), Alexandre Bedard, Ronny Stiftel, Wang Yu(Cyberserval), Junsung Lee(Trend Micro Zero Day Initiative), Jex Amro, Zhongquan Li@@Guluisacat, Ye Zhang@@VAR10CK(Baidu Security), Mateusz Krzywicki@@krzywix, Garrett Moon(Excited Pixel LLC), Arsenii Kostromin (0x3c3e), Ben Roeder, Toomas Römer, Jaime Bertran, Noah Gregory (wts.dev), Un3xploitable(CW Research Inc), Bohdan Stasiuk@@Bohdan_Stasiuk(CW Research Inc), Pedro Tôrres@@t0rr3sp3dr0, Mickey Jin@@patch1t(Kandji), Csaba Fitzl@@theevilbit(Kandji), an anonymous researcher(Dawn Security Lab of JD), Yinyi Wu@@_3ndy1(Dawn Security Lab of JD), Narendra Bhati(Cyber Security at Suma Soft Pvt), Manager(Cyber Security at Suma Soft Pvt), Pune (India), Lucas Di Tomase, Ryan Dowd@@_rdowd, Gergely Kalman@@gergely_kalman, Csaba Fitzl@@theevilbit, Michael DePlante@@izobashi(Trend Micro Zero Day Initiative), Halle Winkler, Politepix (theoffcuts.org), Bing Shi(Alibaba Group), Wenchao Li(Alibaba Group), Xiaolong Bai(Alibaba Group), (Indiana University Bloomington), Luyi Xing(Indiana University Bloomington), dw0r!(Trend Micro Zero Day Initiative), Rodolphe Brunetti@@eisw0lf, Cristian Dinca (icmd.tech), Wojciech Regula(SecuRing), Q1IQ@@q1iqF, P1umer@@p1umer, Bohdan Stasiuk@@Bohdan_Stasiuk, Holger Fuhrmannek, Politepix@@hallewinkler, 냥냥
Affected Software
5 affected componentsFixes available
Apple macOS<14.7.1
14.7.1
macOS<15.1
15.1
macOS<13.7.1
macOS>=14.0<14.7.1
macOS Ventura<13.7.1
13.7.1
Event History
Oct 28, 2024
Data Sourced
via Apple·12:00 AM
DescriptionWeaknessAffected Software
Updated
via Apple·12:00 AM
DescriptionWeakness
Updated
via Apple·12:00 AM
DescriptionWeaknessAffected Software
Updated
via Apple·12:00 AM
Affected Software
CVE Published
via MITRE·09:08 PM
Data Sourced
via MITRE·09:08 PM
DescriptionWeakness
Data Sourced
via NVD·09:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-44270?
CVE-2024-44270 is classified as a high-severity vulnerability due to its ability to allow sandboxed processes to bypass restrictions.
2
How do I fix CVE-2024-44270?
To fix CVE-2024-44270, update to macOS Ventura 13.7.1 or macOS Sonoma 14.7.1.
3
What systems are affected by CVE-2024-44270?
CVE-2024-44270 affects macOS versions prior to 13.7.1 and between 14.0 and 14.7.1.
4
What type of issue is CVE-2024-44270?
CVE-2024-44270 is a logic issue that was addressed with improved validation against sandbox restrictions.
5
Can a sandboxed process exploit CVE-2024-44270?
Yes, a sandboxed process may exploit CVE-2024-44270 to circumvent sandbox restrictions.