CVE-2024-54505: Use After Free
A type confusion issue was addressed with improved memory handling. This issue is fixed in iPadOS 17.7.3, watchOS 11.2, visionOS 2.2, tvOS 18.2, macOS Sequoia 15.2, Safari 18.2, iOS 18.2 and iPadOS 18.2. Processing maliciously crafted web content may lead to memory corruption.
Other sources
A type confusion issue was addressed with improved memory handling. This issue is fixed in Safari 18.2, iOS 18.2 and iPadOS 18.2, iPadOS 17.7.3, macOS Sequoia 15.2, tvOS 18.2, visionOS 2.2, watchOS 11.2. Processing maliciously crafted web content may lead to memory corruption.
— MITRE
Accounts. A logic issue was addressed with improved file handling.
— Apple
APFS. This issue was addressed through improved state management.
— Apple
Apple Account. The issue was addressed with improved handling of protocols.
— Apple
Apple Software Restore. The issue was addressed with improved checks.
— Apple
Credit
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/webkit2gtkto a version that resolves this vulnerability.Fixed in 2.46.5-1~deb11u1Fixed in 2.46.5-1~deb12u1Fixed in 2.46.5-1 - Upgrade
Upgrade
debian/wpewebkitto a version that resolves this vulnerability.Fixed in 2.46.5-1 - Upgrade
Upgrade
visionOSto a version that resolves this vulnerability.Fixed in 2.2 - Upgrade
Upgrade
Safarito a version that resolves this vulnerability.Fixed in 18.2 - Upgrade
Upgrade
Apple iOS, iPadOS, and watchOSto a version that resolves this vulnerability.Fixed in 11.2 - Upgrade
Upgrade
tvOSto a version that resolves this vulnerability.Fixed in 18.2 - Upgrade
Upgrade
Apple iOS and iPadOSto a version that resolves this vulnerability.Fixed in 18.2 - Upgrade
Upgrade
Apple iOS, iPadOS, and macOSto a version that resolves this vulnerability.Fixed in 18.2 - Upgrade
Upgrade
Apple iOS, iPadOS, and macOSto a version that resolves this vulnerability.Fixed in 17.7.3 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 15.2 - Upgrade
Upgrade
iOSto a version that resolves this vulnerability.Fixed in 18.2 - Upgrade
Upgrade
iPadOSto a version that resolves this vulnerability.Fixed in 18.2 - Upgrade
Upgrade
iPadOSto a version that resolves this vulnerability.Fixed in 17.7.3 - Upgrade
Upgrade
macOS Sequoiato a version that resolves this vulnerability.Fixed in 15.2 - Upgrade
Upgrade
watchOSto a version that resolves this vulnerability.Fixed in 11.2 - Configuration
Sanitize logging and improve redaction of sensitive/private data in log entries.
Logging private data redaction = improved
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2024-54541
- CVE-2024-54513
- CVE-2024-54486
- CVE-2024-54478
- CVE-2024-54499
- CVE-2024-54500
- CVE-2024-44245
- CVE-2024-54494
- CVE-2024-45490
- CVE-2024-54525
- CVE-2024-54530
- CVE-2024-54492
- CVE-2024-54497
- CVE-2024-54501
- CVE-2024-45306
- CVE-2024-54479
- CVE-2024-54502
- CVE-2024-54508
- CVE-2024-54505
- CVE-2024-54534
- CVE-2024-54543
- CVE-2024-44246
- CVE-2024-54542
- CVE-2024-40864
- CVE-2024-54526
- CVE-2024-54527
- CVE-2024-54512
- CVE-2024-54517
- CVE-2024-54518
- CVE-2024-54522
- CVE-2024-54523
- CVE-2024-54468
- CVE-2024-54510
- CVE-2024-54514
- CVE-2024-44225
- CVE-2024-54488
- CVE-2024-54503
- CVE-2024-54550
- CVE-2024-54507
- CVE-2024-44276
- CVE-2024-54485
- CVE-2024-44201
- CVE-2025-24091
- CVE-2024-54477
- CVE-2024-44220
- CVE-2024-54490
- CVE-2024-54509
- CVE-2024-54568
- CVE-2024-54529
- CVE-2024-44271
- CVE-2024-44300
- CVE-2024-54466
- CVE-2024-54489
- CVE-2024-54547
- CVE-2024-54519
- CVE-2024-44291
- CVE-2024-54506
- CVE-2024-54531
- CVE-2024-54465
- CVE-2024-54491
- CVE-2024-54484
- CVE-2024-54536
- CVE-2024-54504
- CVE-2024-54474
- CVE-2024-54476
- CVE-2016-1246
- CVE-2023-31484
- CVE-2023-31486
- CVE-2023-47100
- CVE-2023-32395
- CVE-2024-54537
- CVE-2024-54559
- CVE-2024-54557
- CVE-2024-54516
- CVE-2024-54515
- CVE-2024-54528
- CVE-2024-54524
- CVE-2024-54498
- CVE-2024-54493
- CVE-2024-54533
- CVE-2024-44243
- CVE-2024-44224
- CVE-2024-54495
- CVE-2024-54549
- CVE-2024-54475
- CVE-2024-54520
- CVE-2024-54539
- CVE-2024-54565
Frequently Asked Questions
What is the severity of CVE-2024-54505?
CVE-2024-54505 has a medium severity level due to potential memory corruption from processing malicious web content.
How do I fix CVE-2024-54505?
To fix CVE-2024-54505, update your affected Apple devices to the latest software versions including iPadOS 17.7.3, iOS 18.2, macOS Sequoia 15.2, and others.
Which Apple products are affected by CVE-2024-54505?
CVE-2024-54505 affects several Apple products including Safari, iPadOS, iPhone OS, macOS, tvOS, visionOS, and watchOS.
What are the consequences of not addressing CVE-2024-54505?
Not addressing CVE-2024-54505 may leave users vulnerable to memory corruption and potential exploitation from malicious web content.
When was CVE-2024-54505 discovered?
CVE-2024-54505 was addressed in software updates released on or before February 2024.