Apple Security Advisories · June 2024 — Apple Security Advisories
8 advisories 8 CVEs 1 EXPLOITED

Apple-vendor CVEs for 2024-06. Mirrored into Vulnetix VDB.

Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity). 1 is already weaponised in the wild — see the Exploited section.

What would you fix first?

The advisories below are ordered by the Vulnetix risk prioritization strategy: exploitation evidence first, scores second. On the interactive page you can switch to three other lenses.

Advisories

CVE-2024-6387

OtherExploitedVulnCheck KEV listedHIGH2024-06-30

A security regression (CVE-2006-5051) was discovered in OpenSSH's server (sshd). There is a race condition which can lead sshd to handle some signals in an unsafe manner. An unauthenticated, remote attacker may be able to trigger it by failing to authe...

CVEs:CVE-2024-6387

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2024-27812

visionOSActive exploitation (sightings)HIGH2024-06-10

A logic issue was addressed with improved file handling. This issue is fixed in visionOS 1.2. Processing web content may lead to a denial-of-service.

CVEs:CVE-2024-27812

Affected products

ProductStatusVendorPackageEcosystem
visionos affected apple
Upstream advisory

CVE-2024-27867

OtherActive exploitation (sightings)CRITICAL2024-06-26

An authentication issue was addressed with improved state management. This issue is fixed in AirPods Firmware Update 6A326, AirPods Firmware Update 6F8, and Beats Firmware Update 6F8. When your headphones are seeking a connection request to one of your...

CVEs:CVE-2024-27867

Affected products

ProductStatusVendorPackageEcosystem
airpods_firmware affected apple
airpods_max_firmware affected apple
airpods_pro_firmware affected apple
beats_fit_pro_firmware affected apple
powerbeats_firmware affected apple
Upstream advisory

CVE-2022-32897

macOSPoC exploitCRITICAL2024-06-10

A memory corruption issue was addressed with improved validation. This issue is fixed in macOS Monterey 12.5. Processing a maliciously crafted tiff file may lead to arbitrary code execution.

CVEs:CVE-2022-32897

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2023-40389

macOSPoC exploitMEDIUM2024-06-10

The issue was addressed with improved restriction of data container access. This issue is fixed in macOS Ventura 13.6.5, macOS Monterey 12.7.4. An app may be able to access sensitive user data.

CVEs:CVE-2023-40389

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2024-27792

macOSPoC exploitHIGH2024-06-10

This issue was addressed by adding an additional prompt for user consent. This issue is fixed in macOS Sonoma 14.4. An app may be able to access user-sensitive data.

CVEs:CVE-2024-27792

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2022-48578

macOSPoC exploitHIGH2024-06-10

An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Monterey 12.5. Processing an AppleScript may result in unexpected termination or disclosure of process memory.

CVEs:CVE-2022-48578

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2024-27814

watchOSCoalition ESS < 30%LOW2024-06-10

This issue was addressed through improved state management. This issue is fixed in watchOS 10.5. A person with physical access to a device may be able to view contact information from the lock screen.

CVEs:CVE-2024-27814

Affected products

ProductStatusVendorPackageEcosystem
watchos affected apple
Upstream advisory

Need live exploit intelligence?

Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.