CVE-2024-54542: Race Condition
Accounts. A logic issue was addressed with improved file handling.
Other sources
An authentication issue was addressed with improved state management. This issue is fixed in Safari 18.2, iOS 18.2 and iPadOS 18.2, macOS Sequoia 15.2, watchOS 11.2. Private Browsing tabs may be accessed without authentication.
— MITRE
APFS. This issue was addressed through improved state management.
— Apple
Apple Account. The issue was addressed with improved handling of protocols.
— Apple
Apple Software Restore. The issue was addressed with improved checks.
— Apple
AppleGraphicsControl. The issue was addressed with improved memory handling.
— Apple
Credit
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2024-44246
- CVE-2024-54542
- CVE-2024-54479
- CVE-2024-54502
- CVE-2024-54508
- CVE-2024-54505
- CVE-2024-54534
- CVE-2024-54543
- CVE-2024-54541
- CVE-2024-40864
- CVE-2024-54526
- CVE-2024-54527
- CVE-2024-54513
- CVE-2024-54512
- CVE-2024-54486
- CVE-2024-54478
- CVE-2024-54499
- CVE-2024-54500
- CVE-2024-54517
- CVE-2024-54518
- CVE-2024-54522
- CVE-2024-54523
- CVE-2024-54468
- CVE-2024-54494
- CVE-2024-54510
- CVE-2024-45490
- CVE-2024-54514
- CVE-2024-44225
- CVE-2024-54525
- CVE-2024-54530
- CVE-2024-54497
- CVE-2024-54501
- CVE-2024-45306
- CVE-2024-54488
- CVE-2024-54503
- CVE-2024-54550
- CVE-2024-54507
- CVE-2024-44245
- CVE-2024-44276
- CVE-2024-54492
- CVE-2024-54485
- CVE-2024-54477
- CVE-2024-44220
- CVE-2024-54490
- CVE-2024-54509
- CVE-2024-54568
- CVE-2024-54529
- CVE-2024-44271
- CVE-2024-44300
- CVE-2024-54466
- CVE-2024-54489
- CVE-2024-54547
- CVE-2024-54519
- CVE-2024-44291
- CVE-2024-54506
- CVE-2024-54531
- CVE-2024-54465
- CVE-2024-54491
- CVE-2024-54484
- CVE-2024-54536
- CVE-2024-54504
- CVE-2024-54474
- CVE-2024-54476
- CVE-2016-1246
- CVE-2023-31484
- CVE-2023-31486
- CVE-2023-47100
- CVE-2023-32395
- CVE-2024-54537
- CVE-2024-54559
- CVE-2024-54557
- CVE-2024-54516
- CVE-2024-54515
- CVE-2024-54528
- CVE-2024-54524
- CVE-2024-54498
- CVE-2024-54493
- CVE-2024-54533
- CVE-2024-44243
- CVE-2024-44224
- CVE-2024-54495
- CVE-2024-54549
- CVE-2024-54475
- CVE-2024-54520
- CVE-2024-54539
- CVE-2024-54565
Frequently Asked Questions
What is the severity of CVE-2024-54542?
CVE-2024-54542 is classified with moderate severity due to its impact on authentication and state management.
How do I fix CVE-2024-54542?
To fix CVE-2024-54542, update Safari to version 18.2 or update your affected Apple devices to their respective patched versions.
What is the impact of CVE-2024-54542?
CVE-2024-54542 allows unauthorized access to Private Browsing tabs, potentially exposing sensitive information.
Which products are affected by CVE-2024-54542?
CVE-2024-54542 affects Apple Safari, macOS Sequoia, watchOS, iOS, and iPadOS prior to their respective version updates.
When was CVE-2024-54542 disclosed?
CVE-2024-54542 was disclosed as an authentication vulnerability in the affected Apple software products.