CVE-2024-54489: Path Traversal
A path handling issue was addressed with improved validation. This issue is fixed in macOS Sequoia 15.2, macOS Sonoma 14.7.2, macOS Ventura 13.7.2. Running a mount command may unexpectedly execute arbitrary code.
Other sources
Accounts. A logic issue was addressed with improved file handling.
— Apple
APFS. This issue was addressed through improved state management.
— Apple
Apple Account. The issue was addressed with improved handling of protocols.
— Apple
Apple Software Restore. The issue was addressed with improved checks.
— Apple
AppleGraphicsControl. The issue was addressed with improved memory handling.
— Apple
Credit
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2024-54488
- CVE-2024-54541
- CVE-2024-54477
- CVE-2024-44220
- CVE-2024-54527
- CVE-2024-54526
- CVE-2024-54509
- CVE-2024-54529
- CVE-2024-44300
- CVE-2024-54466
- CVE-2024-54489
- CVE-2024-54547
- CVE-2024-54519
- CVE-2024-54486
- CVE-2024-54478
- CVE-2024-54500
- CVE-2024-54468
- CVE-2024-54494
- CVE-2024-54510
- CVE-2024-44245
- CVE-2024-44201
- CVE-2024-45490
- CVE-2024-54514
- CVE-2024-44225
- CVE-2024-54474
- CVE-2024-54476
- CVE-2024-54537
- CVE-2024-54501
- CVE-2024-44248
- CVE-2024-54557
- CVE-2024-54516
- CVE-2024-54528
- CVE-2024-54498
- CVE-2024-44291
- CVE-2024-44224
- CVE-2024-54495
- CVE-2024-54520
- CVE-2024-54475
- CVE-2024-45306
- CVE-2024-54539
- CVE-2024-40864
- CVE-2024-54490
- CVE-2024-54568
- CVE-2024-54550
- CVE-2024-44271
- CVE-2024-54513
- CVE-2024-54499
- CVE-2024-54517
- CVE-2024-54518
- CVE-2024-54522
- CVE-2024-54523
- CVE-2024-54506
- CVE-2024-54507
- CVE-2024-54531
- CVE-2024-54465
- CVE-2024-54491
- CVE-2024-54484
- CVE-2024-54525
- CVE-2024-54536
- CVE-2024-54504
- CVE-2024-54530
- CVE-2024-54492
- CVE-2016-1246
- CVE-2023-31484
- CVE-2023-31486
- CVE-2023-47100
- CVE-2023-32395
- CVE-2024-54497
- CVE-2024-44246
- CVE-2024-54542
- CVE-2024-54559
- CVE-2024-54515
- CVE-2024-54524
- CVE-2024-54493
- CVE-2024-54533
- CVE-2024-44243
- CVE-2024-54549
- CVE-2024-54485
- CVE-2024-54479
- CVE-2024-54502
- CVE-2024-54508
- CVE-2024-54505
- CVE-2024-54534
- CVE-2024-54543
- CVE-2024-54565
Frequently Asked Questions
What is the severity of CVE-2024-54489?
CVE-2024-54489 has been classified with a high severity due to the potential for arbitrary code execution.
How do I fix CVE-2024-54489?
To fix CVE-2024-54489, update your macOS to macOS Sequoia 15.2, macOS Ventura 13.7.2, or macOS Sonoma 14.7.2.
What systems are affected by CVE-2024-54489?
CVE-2024-54489 affects macOS versions prior to 13.7.2, between 14.0 and 14.7.2, and between 15.0 and 15.2.
What kind of issue is CVE-2024-54489?
CVE-2024-54489 is a path handling issue that can lead to arbitrary code execution if exploited.
Is CVE-2024-54489 a remote or local vulnerability?
CVE-2024-54489 is considered a local vulnerability requiring execution of specific commands on the affected system.