Advisories
OtherExploitedVulnCheck KEV listedHIGH2024-06-30
A security regression (CVE-2006-5051) was discovered in OpenSSH's server (sshd). There is a race condition which can lead sshd to handle some signals in an unsafe manner. An unauthenticated, remote attacker may be able to trigger it by failing to authe...
CVEs:CVE-2024-6387
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| macos |
affected |
apple |
— |
— |
visionOSActive exploitation (sightings)HIGH2024-06-10
A logic issue was addressed with improved file handling. This issue is fixed in visionOS 1.2. Processing web content may lead to a denial-of-service.
CVEs:CVE-2024-27812
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| visionos |
affected |
apple |
— |
— |
OtherActive exploitation (sightings)CRITICAL2024-06-26
An authentication issue was addressed with improved state management. This issue is fixed in AirPods Firmware Update 6A326, AirPods Firmware Update 6F8, and Beats Firmware Update 6F8. When your headphones are seeking a connection request to one of your...
CVEs:CVE-2024-27867
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| airpods_firmware |
affected |
apple |
— |
— |
| airpods_max_firmware |
affected |
apple |
— |
— |
| airpods_pro_firmware |
affected |
apple |
— |
— |
| beats_fit_pro_firmware |
affected |
apple |
— |
— |
| powerbeats_firmware |
affected |
apple |
— |
— |
macOSPoC exploitCRITICAL2024-06-10
A memory corruption issue was addressed with improved validation. This issue is fixed in macOS Monterey 12.5. Processing a maliciously crafted tiff file may lead to arbitrary code execution.
CVEs:CVE-2022-32897
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| macos |
affected |
apple |
— |
— |
macOSPoC exploitMEDIUM2024-06-10
The issue was addressed with improved restriction of data container access. This issue is fixed in macOS Ventura 13.6.5, macOS Monterey 12.7.4. An app may be able to access sensitive user data.
CVEs:CVE-2023-40389
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| macos |
affected |
apple |
— |
— |
macOSPoC exploitHIGH2024-06-10
This issue was addressed by adding an additional prompt for user consent. This issue is fixed in macOS Sonoma 14.4. An app may be able to access user-sensitive data.
CVEs:CVE-2024-27792
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| macos |
affected |
apple |
— |
— |
macOSPoC exploitHIGH2024-06-10
An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Monterey 12.5. Processing an AppleScript may result in unexpected termination or disclosure of process memory.
CVEs:CVE-2022-48578
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| macos |
affected |
apple |
— |
— |
watchOSCoalition ESS < 30%LOW2024-06-10
This issue was addressed through improved state management. This issue is fixed in watchOS 10.5. A person with physical access to a device may be able to view contact information from the lock screen.
CVEs:CVE-2024-27814
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| watchos |
affected |
apple |
— |
— |