VORANT. Threat Intelligence Sign in Get the full feed

Apple patches 50+ flaws across iOS, macOS ecosystems

high vulnerability

Apple released security updates for Safari, iOS, iPadOS, macOS, watchOS, tvOS, and visionOS addressing over 50 vulnerabilities, including critical flaws enabling arbitrary code execution.

Apple has issued comprehensive security updates across its entire product ecosystem to address multiple vulnerabilities affecting Safari 18.2, iOS/iPadOS 18.2 and 17.7.3, macOS Sequoia 15.2, Sonoma 14.7.2, Ventura 13.7.2, watchOS 11.2, tvOS 18.2, and visionOS 2.2. The most severe vulnerabilities could allow arbitrary code execution with the privileges of the logged-on user, including kernel-level execution in some cases. Critical flaws include CVE-2024-54529, which allows apps to execute arbitrary code with kernel privileges, and CVE-2024-45490, which could cause unexpected app termination or arbitrary code execution.

The update addresses a broad range of security issues beyond code execution, including sandbox escapes, privilege escalation vulnerabilities, information disclosure flaws, and memory corruption issues in WebKit. Several vulnerabilities affect fundamental system components including the kernel, file system protections, and cryptographic implementations. Additional concerns include privacy-related issues such as Private Relay IP address disclosure when adding websites to Safari Reading List, and notification content visibility from lock screens on iOS and iPadOS devices.

MS-ISAC rates the risk as high for government and business environments, and medium for home users. No active exploitation has been reported for any of these vulnerabilities. Apple users should apply updates immediately after appropriate testing, with particular urgency for organizations operating with administrative privileges on affected systems.

Mentioned in this report

Vulnerabilities CVE-2024-44201CVE-2024-44220CVE-2024-44224CVE-2024-44225CVE-2024-44245CVE-2024-44246CVE-2024-44291CVE-2024-44300CVE-2024-45490CVE-2024-54465CVE-2024-54466CVE-2024-54474CVE-2024-54476CVE-2024-54477CVE-2024-54479CVE-2024-54484CVE-2024-54485CVE-2024-54486CVE-2024-54489CVE-2024-54490CVE-2024-54492CVE-2024-54494CVE-2024-54498CVE-2024-54500CVE-2024-54501CVE-2024-54502CVE-2024-54503CVE-2024-54504CVE-2024-54505CVE-2024-54506CVE-2024-54508CVE-2024-54510CVE-2024-54513CVE-2024-54514CVE-2024-54515CVE-2024-54526CVE-2024-54527CVE-2024-54529CVE-2024-54531CVE-2024-54534

Source reporting: https://www.cisecurity.org/advisory/multiple-vulnerabilities-in-apple-products-could-allow-for-arbitrary-code-execution_2024-138

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free