CVE-2024-54502: Use After Free
Accounts. A logic issue was addressed with improved file handling.
Other sources
Accounts. This issue was addressed with improved data access restriction.
— Apple
AirPlay. A null pointer dereference was addressed with improved input validation.
— Apple
AirPlay. A type confusion issue was addressed with improved checks.
— Apple
AirPlay. A use-after-free issue was addressed with improved memory management.
— Apple
AirPlay. An access issue was addressed with improved access restrictions.
— Apple
Credit
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/webkit2gtkto a version that resolves this vulnerability.Fixed in 2.46.5-1~deb11u1Fixed in 2.46.5-1~deb12u1Fixed in 2.46.5-1 - Upgrade
Upgrade
debian/wpewebkitto a version that resolves this vulnerability.Fixed in 2.46.5-1 - Upgrade
Upgrade
visionOSto a version that resolves this vulnerability.Fixed in 2.2 - Upgrade
Upgrade
Safarito a version that resolves this vulnerability.Fixed in 18.2 - Upgrade
Upgrade
Apple iOS, iPadOS, and watchOSto a version that resolves this vulnerability.Fixed in 11.2 - Upgrade
Upgrade
tvOSto a version that resolves this vulnerability.Fixed in 18.2 - Upgrade
Upgrade
Apple iOS and iPadOSto a version that resolves this vulnerability.Fixed in 18.2 - Upgrade
Upgrade
Apple iOS, iPadOS, and macOSto a version that resolves this vulnerability.Fixed in 18.2 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 17.7.6 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 15.2 - Upgrade
Upgrade
iOSto a version that resolves this vulnerability.Fixed in 18.2 - Upgrade
Upgrade
iPadOSto a version that resolves this vulnerability.Fixed in 18.2 - Upgrade
Upgrade
iPadOSto a version that resolves this vulnerability.Fixed in 17.7.6 - Upgrade
Upgrade
macOS Sequoiato a version that resolves this vulnerability.Fixed in 15.2 - Upgrade
Upgrade
watchOSto a version that resolves this vulnerability.Fixed in 11.2 - Configuration
Sanitize logging / improve private data redaction for log entries (the issue was resolved by sanitizing logging and addressed with improved redaction of sensitive information).
Logging sensitive log redaction/sanitizing = sanitized - Compensating control
Enable hardened runtime (the issue was addressed by enabling hardened runtime).
- Compensating control
Use HTTPS when sending information over the network (the issue was addressed by using HTTPS when sending information over the network).
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2024-54541
- CVE-2024-54513
- CVE-2024-54486
- CVE-2024-54478
- CVE-2024-54499
- CVE-2024-54500
- CVE-2024-44245
- CVE-2024-54494
- CVE-2024-45490
- CVE-2024-54525
- CVE-2024-54530
- CVE-2024-54492
- CVE-2024-54497
- CVE-2024-54501
- CVE-2024-45306
- CVE-2024-54479
- CVE-2024-54502
- CVE-2024-54508
- CVE-2024-54505
- CVE-2024-54534
- CVE-2024-54543
- CVE-2024-44246
- CVE-2024-54542
- CVE-2024-40864
- CVE-2024-54526
- CVE-2024-54527
- CVE-2024-54512
- CVE-2024-54517
- CVE-2024-54518
- CVE-2024-54522
- CVE-2024-54523
- CVE-2024-54468
- CVE-2024-54510
- CVE-2024-54514
- CVE-2024-44225
- CVE-2024-54488
- CVE-2024-54503
- CVE-2024-54550
- CVE-2024-54507
- CVE-2024-44276
- CVE-2024-54485
- CVE-2025-24221
- CVE-2025-24131
- CVE-2025-24270
- CVE-2025-24271
- CVE-2025-24177
- CVE-2025-24179
- CVE-2025-24251
- CVE-2025-31197
- CVE-2025-24252
- CVE-2025-30445
- CVE-2025-24206
- CVE-2025-43205
- CVE-2025-24243
- CVE-2025-24244
- CVE-2025-24237
- CVE-2025-30429
- CVE-2025-24212
- CVE-2025-24215
- CVE-2025-24230
- CVE-2025-24085
- CVE-2025-24190
- CVE-2025-24211
- CVE-2025-31203
- CVE-2024-9681
- CVE-2025-30447
- CVE-2025-24210
- CVE-2025-30432
- CVE-2025-24203
- CVE-2025-27113
- CVE-2024-56171
- CVE-2025-24178
- CVE-2025-30426
- CVE-2025-30428
- CVE-2025-24173
- CVE-2025-24113
- CVE-2025-30471
- CVE-2025-30465
- CVE-2025-30433
- CVE-2025-24198
- CVE-2025-24205
- CVE-2025-24201
- CVE-2025-30425
- CVE-2025-24216
- CVE-2025-24264
- CVE-2025-30427
- CVE-2025-24209
- CVE-2024-54477
- CVE-2024-44220
- CVE-2024-54490
- CVE-2024-54509
- CVE-2024-54568
- CVE-2024-54529
- CVE-2024-44271
- CVE-2024-44300
- CVE-2024-54466
- CVE-2024-54489
- CVE-2024-54547
- CVE-2024-54519
- CVE-2024-44291
- CVE-2024-54506
- CVE-2024-54531
- CVE-2024-54465
- CVE-2024-54491
- CVE-2024-54484
- CVE-2024-54536
- CVE-2024-54504
- CVE-2024-54474
- CVE-2024-54476
- CVE-2016-1246
- CVE-2023-31484
- CVE-2023-31486
- CVE-2023-47100
- CVE-2023-32395
- CVE-2024-54537
- CVE-2024-54559
- CVE-2024-54557
- CVE-2024-54516
- CVE-2024-54515
- CVE-2024-54528
- CVE-2024-54524
- CVE-2024-54498
- CVE-2024-54493
- CVE-2024-54533
- CVE-2024-44243
- CVE-2024-44224
- CVE-2024-54495
- CVE-2024-54549
- CVE-2024-54475
- CVE-2024-54520
- CVE-2024-54539
- CVE-2024-54565
Frequently Asked Questions
What is the severity of CVE-2024-54502?
CVE-2024-54502 has a high severity rating due to the logic issue affecting file handling and memory management.
How do I fix CVE-2024-54502?
To fix CVE-2024-54502, update your affected software to the latest version as specified in the remedy section.
What software is affected by CVE-2024-54502?
CVE-2024-54502 affects various software products, including Apple macOS, iOS, iPadOS, Safari, and WebKit packages.
What types of issues are addressed by CVE-2024-54502?
CVE-2024-54502 addresses issues related to logic errors, improved memory handling, and state management improvements.
Are there any known exploits for CVE-2024-54502?
There are currently no known public exploits specifically targeting CVE-2024-54502.