CVE-2024-54478: Input Validation
Accounts. A logic issue was addressed with improved file handling.
Other sources
AirPlay. A type confusion issue was addressed with improved checks.
— Apple
An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in iOS 18.2 and iPadOS 18.2, iPadOS 17.7.4, macOS Sequoia 15.2, macOS Sonoma 14.7.2, tvOS 18.2, visionOS 2.2, watchOS 11.2. Processing maliciously crafted web content may lead to an unexpected process crash.
— MITRE
APFS. This issue was addressed through improved state management.
— Apple
Apple Account. The issue was addressed with improved handling of protocols.
— Apple
Apple Software Restore. The issue was addressed with improved checks.
— Apple
Credit
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2024-54541
- CVE-2024-54513
- CVE-2024-54486
- CVE-2024-54478
- CVE-2024-54499
- CVE-2024-54500
- CVE-2024-44245
- CVE-2024-54494
- CVE-2024-45490
- CVE-2024-54525
- CVE-2024-54530
- CVE-2024-54492
- CVE-2024-54497
- CVE-2024-54501
- CVE-2024-45306
- CVE-2024-54479
- CVE-2024-54502
- CVE-2024-54508
- CVE-2024-54505
- CVE-2024-54534
- CVE-2024-54543
- CVE-2024-40864
- CVE-2024-54526
- CVE-2024-54527
- CVE-2024-54512
- CVE-2024-54517
- CVE-2024-54518
- CVE-2024-54522
- CVE-2024-54523
- CVE-2024-54468
- CVE-2024-54510
- CVE-2024-54514
- CVE-2024-44225
- CVE-2024-54542
- CVE-2024-54488
- CVE-2024-54503
- CVE-2024-54550
- CVE-2024-54507
- CVE-2024-44276
- CVE-2024-44246
- CVE-2024-54485
- CVE-2025-24137
- CVE-2025-24127
- CVE-2025-24161
- CVE-2025-24160
- CVE-2025-24163
- CVE-2025-24123
- CVE-2025-24124
- CVE-2025-24184
- CVE-2025-24102
- CVE-2025-24086
- CVE-2025-24118
- CVE-2025-24159
- CVE-2025-24117
- CVE-2024-55549
- CVE-2025-24855
- CVE-2025-24104
- CVE-2025-24149
- CVE-2024-54477
- CVE-2024-44220
- CVE-2024-54509
- CVE-2024-54529
- CVE-2024-44300
- CVE-2024-54466
- CVE-2024-54489
- CVE-2024-54547
- CVE-2024-54519
- CVE-2024-44201
- CVE-2024-54474
- CVE-2024-54476
- CVE-2024-54537
- CVE-2024-44248
- CVE-2024-54557
- CVE-2024-54516
- CVE-2024-54528
- CVE-2024-54498
- CVE-2024-44291
- CVE-2024-44224
- CVE-2024-54495
- CVE-2024-54520
- CVE-2024-54475
- CVE-2024-54539
- CVE-2024-54490
- CVE-2024-54568
- CVE-2024-44271
- CVE-2024-54506
- CVE-2024-54531
- CVE-2024-54465
- CVE-2024-54491
- CVE-2024-54484
- CVE-2024-54536
- CVE-2024-54504
- CVE-2016-1246
- CVE-2023-31484
- CVE-2023-31486
- CVE-2023-47100
- CVE-2023-32395
- CVE-2024-54559
- CVE-2024-54515
- CVE-2024-54524
- CVE-2024-54493
- CVE-2024-54533
- CVE-2024-44243
- CVE-2024-54549
- CVE-2024-54565
Frequently Asked Questions
What is the severity of CVE-2024-54478?
CVE-2024-54478 has been classified as a vulnerability associated with out-of-bounds access that affects various Apple operating systems.
How do I fix CVE-2024-54478?
To resolve CVE-2024-54478, update your device to the latest available version such as iOS 18.2, iPadOS 18.2, or other affected software versions listed by Apple.
Which Apple devices are affected by CVE-2024-54478?
CVE-2024-54478 affects several Apple devices running outdated versions of iOS, iPadOS, tvOS, watchOS, and macOS.
What type of vulnerability is CVE-2024-54478?
CVE-2024-54478 is an out-of-bounds access vulnerability that could lead to unexpected process crashes when processing maliciously crafted web content.
When was CVE-2024-54478 fixed?
CVE-2024-54478 was addressed in the updates released on various dates for affected Apple operating systems, specifically in versions 17.7.4 and 18.2.