CVE-2024-54498: Race Condition
A path handling issue was addressed with improved validation. This issue is fixed in macOS Sequoia 15.2, macOS Sonoma 14.7.2, macOS Ventura 13.7.2. An app may be able to break out of its sandbox.
Other sources
Accounts. A logic issue was addressed with improved file handling.
— Apple
APFS. This issue was addressed through improved state management.
— Apple
Apple Account. The issue was addressed with improved handling of protocols.
— Apple
Apple Software Restore. The issue was addressed with improved checks.
— Apple
AppleGraphicsControl. The issue was addressed with improved memory handling.
— Apple
Credit
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2024-54488
- CVE-2024-54541
- CVE-2024-54477
- CVE-2024-44220
- CVE-2024-54527
- CVE-2024-54526
- CVE-2024-54509
- CVE-2024-54529
- CVE-2024-44300
- CVE-2024-54466
- CVE-2024-54489
- CVE-2024-54547
- CVE-2024-54519
- CVE-2024-54486
- CVE-2024-54478
- CVE-2024-54500
- CVE-2024-54468
- CVE-2024-54494
- CVE-2024-54510
- CVE-2024-44245
- CVE-2024-44201
- CVE-2024-45490
- CVE-2024-54514
- CVE-2024-44225
- CVE-2024-54474
- CVE-2024-54476
- CVE-2024-54537
- CVE-2024-54501
- CVE-2024-44248
- CVE-2024-54557
- CVE-2024-54516
- CVE-2024-54528
- CVE-2024-54498
- CVE-2024-44291
- CVE-2024-44224
- CVE-2024-54495
- CVE-2024-54520
- CVE-2024-54475
- CVE-2024-45306
- CVE-2024-54539
- CVE-2024-40864
- CVE-2024-54490
- CVE-2024-54568
- CVE-2024-54550
- CVE-2024-44271
- CVE-2024-54513
- CVE-2024-54499
- CVE-2024-54517
- CVE-2024-54518
- CVE-2024-54522
- CVE-2024-54523
- CVE-2024-54506
- CVE-2024-54507
- CVE-2024-54531
- CVE-2024-54465
- CVE-2024-54491
- CVE-2024-54484
- CVE-2024-54525
- CVE-2024-54536
- CVE-2024-54504
- CVE-2024-54530
- CVE-2024-54492
- CVE-2016-1246
- CVE-2023-31484
- CVE-2023-31486
- CVE-2023-47100
- CVE-2023-32395
- CVE-2024-54497
- CVE-2024-44246
- CVE-2024-54542
- CVE-2024-54559
- CVE-2024-54515
- CVE-2024-54524
- CVE-2024-54493
- CVE-2024-54533
- CVE-2024-44243
- CVE-2024-54549
- CVE-2024-54485
- CVE-2024-54479
- CVE-2024-54502
- CVE-2024-54508
- CVE-2024-54505
- CVE-2024-54534
- CVE-2024-54543
- CVE-2024-54565
Frequently Asked Questions
What is the severity of CVE-2024-54498?
CVE-2024-54498 has not been assigned a CVSS score but poses a significant risk as it may allow an app to break out of its sandbox.
How do I fix CVE-2024-54498?
To fix CVE-2024-54498, update your system to macOS Sequoia 15.2, macOS Ventura 13.7.2, or macOS Sonoma 14.7.2.
What types of applications are affected by CVE-2024-54498?
CVE-2024-54498 potentially affects applications running on macOS that utilize sandboxing functionalities.
Can CVE-2024-54498 lead to data breaches?
Yes, CVE-2024-54498 could lead to data breaches if an application successfully escapes its sandbox and accesses restricted files.
Is CVE-2024-54498 being actively exploited?
As of now, there are no confirmed reports of active exploitation related to CVE-2024-54498.