Apple Security Advisories · October 2024 — Apple Security Advisories
89 advisories 89 CVEs 1 EXPLOITED

Apple-vendor CVEs for 2024-10. Mirrored into Vulnetix VDB.

Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity). 1 is already weaponised in the wild — see the Exploited section.

What would you fix first?

The advisories below are ordered by the Vulnetix risk prioritization strategy: exploitation evidence first, scores second. On the interactive page you can switch to three other lenses.

Advisories

CVE-2024-44258

visionOSExploitedVulnCheck KEV listedHIGH2024-10-28

This issue was addressed with improved handling of symlinks. This issue is fixed in iOS 17.7.1 and iPadOS 17.7.1, iOS 18.1 and iPadOS 18.1, tvOS 18.1, visionOS 2.1. Restoring a maliciously crafted backup file may lead to modification of protected syste...

CVEs:CVE-2024-44258

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
tvos affected apple
visionos affected apple
Upstream advisory

CVE-2024-44236

macOSActive exploitation (sightings)MEDIUM2024-10-28

An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in macOS Sequoia 15.1, macOS Sonoma 14.7.1, macOS Ventura 13.7.1. Processing a maliciously crafted file may lead to unexpected app termination.

CVEs:CVE-2024-44236

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2024-44207

iPadOSActive exploitation (sightings)MEDIUM2024-10-03

This issue was addressed with improved checks. This issue is fixed in iOS 18.0.1 and iPadOS 18.0.1. Audio messages in Messages may be able to capture a few seconds of audio before the microphone indicator is activated.

CVEs:CVE-2024-44207

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
Upstream advisory

CVE-2024-44204

iPadOSActive exploitation (sightings)MEDIUM2024-10-03

A logic issue was addressed with improved validation. This issue is fixed in iOS 18.0.1 and iPadOS 18.0.1. A user's saved passwords may be read aloud by VoiceOver.

CVEs:CVE-2024-44204

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
Upstream advisory

CVE-2024-44197

macOSActive exploitation (sightings)MEDIUM2024-10-28

The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.1, macOS Sonoma 14.7.1, macOS Ventura 13.7.1. An app may be able to cause unexpected system termination or corrupt kernel memory.

CVEs:CVE-2024-44197

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2024-54538

visionOSActive exploitation (sightings)HIGH2024-10-28

A denial-of-service issue was addressed with improved input validation. This issue is fixed in iOS 17.7.1 and iPadOS 17.7.1, iOS 18.1 and iPadOS 18.1, macOS Sequoia 15.1, macOS Sonoma 14.7.1, macOS Ventura 13.7.1, tvOS 18.1, visionOS 2.1, watchOS 11.1....

CVEs:CVE-2024-54538

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
tvos affected apple
visionos affected apple
watchos affected apple
Upstream advisory

CVE-2024-44294

macOSActive exploitation (sightings)MEDIUM2024-10-28

A path deletion vulnerability was addressed by preventing vulnerable code from running with privileges. This issue is fixed in macOS Sequoia 15.1, macOS Sonoma 14.7.1, macOS Ventura 13.7.1. An attacker with root privileges may be able to delete protect...

CVEs:CVE-2024-44294

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2024-44297

visionOSActive exploitation (sightings)HIGH2024-10-28

The issue was addressed with improved bounds checks. This issue is fixed in iOS 17.7.1 and iPadOS 17.7.1, iOS 18.1 and iPadOS 18.1, macOS Sequoia 15.1, macOS Sonoma 14.7.1, macOS Ventura 13.7.1, tvOS 18.1, visionOS 2.1, watchOS 11.1. Processing a malic...

CVEs:CVE-2024-44297

Affected products

ProductStatusVendorPackageEcosystem
ipad_os affected apple
iphone_os affected apple
macos affected apple
tvos affected apple
visionos affected apple
watchos affected apple
Upstream advisory

CVE-2024-44282

visionOSActive exploitation (sightings)MEDIUM2024-10-28

An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 17.7.1 and iPadOS 17.7.1, iOS 18.1 and iPadOS 18.1, macOS Sequoia 15.1, macOS Sonoma 14.7.1, macOS Ventura 13.7.1, tvOS 18.1, visionOS 2.1, watchOS 11.1. Par...

CVEs:CVE-2024-44282

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
tvos affected apple
visionos affected apple
watchos affected apple
Upstream advisory

CVE-2024-44248

macOSActive exploitation (sightings)MEDIUM2024-10-28

This issue was addressed through improved state management. This issue is fixed in macOS Sequoia 15.1, macOS Sonoma 14.7.2, macOS Ventura 13.7.2. A user with screen sharing access may be able to view another user's screen.

CVEs:CVE-2024-44248

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2024-44195

macOSActive exploitation (sightings)HIGH2024-10-28

A logic issue was addressed with improved validation. This issue is fixed in macOS Sequoia 15.1. An app may be able to read arbitrary files.

CVEs:CVE-2024-44195

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2024-40867

iPadOSActive exploitation (sightings)CRITICAL2024-10-28

A custom URL scheme handling issue was addressed with improved input validation. This issue is fixed in iOS 18.1 and iPadOS 18.1. A remote attacker may be able to break out of Web Content sandbox.

CVEs:CVE-2024-40867

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
Upstream advisory

CVE-2024-44285

visionOSActive exploitation (sightings)CRITICAL2024-10-28

A use-after-free issue was addressed with improved memory management. This issue is fixed in iOS 18.1 and iPadOS 18.1, macOS Sequoia 15.1, tvOS 18.1, visionOS 2.1, watchOS 11.1. An app may be able to cause unexpected system termination or corrupt kerne...

CVEs:CVE-2024-44285

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
tvos affected apple
visionos affected apple
watchos affected apple
Upstream advisory

CVE-2024-44289

macOSActive exploitation (sightings)HIGH2024-10-28

A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in macOS Sequoia 15.1, macOS Sonoma 14.7.1, macOS Ventura 13.7.1. An app may be able to read sensitive location information.

CVEs:CVE-2024-44289

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2024-44264

macOSActive exploitation (sightings)HIGH2024-10-28

This issue was addressed with improved validation of symlinks. This issue is fixed in macOS Sequoia 15.1, macOS Sonoma 14.7.1, macOS Ventura 13.7.1. A malicious app may be able to create symlinks to protected regions of the disk.

CVEs:CVE-2024-44264

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2024-44284

macOSActive exploitation (sightings)CRITICAL2024-10-28

An out-of-bounds write issue was addressed with improved input validation. This issue is fixed in macOS Sequoia 15.1, macOS Sonoma 14.7.1, macOS Ventura 13.7.1. Parsing a maliciously crafted file may lead to an unexpected app termination.

CVEs:CVE-2024-44284

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2024-44242

iPadOSActive exploitation (sightings)CRITICAL2024-10-28

The issue was addressed with improved bounds checks. This issue is fixed in iOS 18.1 and iPadOS 18.1, macOS Sequoia 15.1. An attacker may be able to cause unexpected system termination or arbitrary code execution in DCP firmware.

CVEs:CVE-2024-44242

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
Upstream advisory

CVE-2024-44237

macOSActive exploitation (sightings)MEDIUM2024-10-28

An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in macOS Sequoia 15.1, macOS Sonoma 14.7.1, macOS Ventura 13.7.1. Processing a maliciously crafted file may lead to unexpected app termination.

CVEs:CVE-2024-44237

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2024-44283

macOSActive exploitation (sightings)MEDIUM2024-10-28

An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Sequoia 15.1, macOS Sonoma 14.7.1, macOS Ventura 13.7.1. Parsing a maliciously crafted file may lead to an unexpected app termination.

CVEs:CVE-2024-44283

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2024-44240

visionOSActive exploitation (sightings)MEDIUM2024-10-28

The issue was addressed with improved checks. This issue is fixed in iOS 17.7.1 and iPadOS 17.7.1, iOS 18.1 and iPadOS 18.1, macOS Sequoia 15.1, macOS Sonoma 14.7.1, macOS Ventura 13.7.1, tvOS 18.1, visionOS 2.1, watchOS 11.1. Processing a maliciously ...

CVEs:CVE-2024-44240

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
tvos affected apple
visionos affected apple
watchos affected apple
Upstream advisory

CVE-2024-44302

visionOSActive exploitation (sightings)MEDIUM2024-10-28

The issue was addressed with improved checks. This issue is fixed in iOS 17.7.1 and iPadOS 17.7.1, iOS 18.1 and iPadOS 18.1, macOS Sequoia 15.1, macOS Sonoma 14.7.1, macOS Ventura 13.7.1, tvOS 18.1, visionOS 2.1, watchOS 11.1. Processing a maliciously ...

CVEs:CVE-2024-44302

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
tvos affected apple
visionos affected apple
watchos affected apple
Upstream advisory

CVE-2024-44279

macOSActive exploitation (sightings)MEDIUM2024-10-28

An out-of-bounds read was addressed with improved input validation. This issue is fixed in macOS Sequoia 15.1, macOS Sonoma 14.7.1, macOS Ventura 13.7.1. Parsing a file may lead to disclosure of user information.

CVEs:CVE-2024-44279

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2024-44231

macOSActive exploitation (sightings)HIGH2024-10-28

This issue was addressed through improved state management. This issue is fixed in macOS Sequoia 15.1. A person with physical access to a Mac may be able to bypass Login Window during a software update.

CVEs:CVE-2024-44231

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2024-54535

visionOSActive exploitation (sightings)MEDIUM2024-10-28

A path handling issue was addressed with improved logic. This issue is fixed in iOS 18.1 and iPadOS 18.1, macOS Sequoia 15.1, visionOS 2.1, watchOS 11.1. An attacker with access to calendar data could also read reminders.

CVEs:CVE-2024-54535

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
visionos affected apple
watchos affected apple
Upstream advisory

CVE-2024-44211

macOSActive exploitation (sightings)HIGH2024-10-28

This issue was addressed with improved validation of symlinks. This issue is fixed in macOS Sequoia 15.1. An app may be able to access user-sensitive data.

CVEs:CVE-2024-44211

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2024-40854

iPadOSActive exploitation (sightings)MEDIUM2024-10-28

A memory initialization issue was addressed with improved memory handling. This issue is fixed in iOS 17.7.1 and iPadOS 17.7.1, iOS 18.1 and iPadOS 18.1, macOS Sequoia 15.1, macOS Sonoma 14.7.1, macOS Ventura 13.7.1. An app may be able to cause unexpec...

CVEs:CVE-2024-40854

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
Upstream advisory

CVE-2024-44234

visionOSActive exploitation (sightings)MEDIUM2024-10-28

The issue was addressed with improved bounds checks. This issue is fixed in iOS 17.7.1 and iPadOS 17.7.1, iOS 18.1 and iPadOS 18.1, macOS Sequoia 15.1, macOS Sonoma 14.7.1, macOS Ventura 13.7.1, tvOS 18.1, visionOS 2.1, watchOS 11.1. Parsing a maliciou...

CVEs:CVE-2024-44234

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
tvos affected apple
visionos affected apple
watchos affected apple
Upstream advisory

CVE-2024-44232

visionOSActive exploitation (sightings)MEDIUM2024-10-28

The issue was addressed with improved bounds checks. This issue is fixed in iOS 17.7.1 and iPadOS 17.7.1, iOS 18.1 and iPadOS 18.1, macOS Sequoia 15.1, macOS Sonoma 14.7.1, macOS Ventura 13.7.1, tvOS 18.1, visionOS 2.1, watchOS 11.1. Parsing a maliciou...

CVEs:CVE-2024-44232

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
tvos affected apple
visionos affected apple
watchos affected apple
Upstream advisory

CVE-2024-44233

visionOSActive exploitation (sightings)MEDIUM2024-10-28

The issue was addressed with improved bounds checks. This issue is fixed in iOS 17.7.1 and iPadOS 17.7.1, iOS 18.1 and iPadOS 18.1, macOS Sequoia 15.1, macOS Sonoma 14.7.1, macOS Ventura 13.7.1, tvOS 18.1, visionOS 2.1, watchOS 11.1. Parsing a maliciou...

CVEs:CVE-2024-44233

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
tvos affected apple
visionos affected apple
watchos affected apple
Upstream advisory

CVE-2024-44215

visionOSActive exploitation (sightings)MEDIUM2024-10-28

This issue was addressed with improved checks. This issue is fixed in iOS 17.7.1 and iPadOS 17.7.1, iOS 18.1 and iPadOS 18.1, macOS Sequoia 15.1, macOS Sonoma 14.7.1, macOS Ventura 13.7.1, tvOS 18.1, visionOS 2.1, watchOS 11.1. Processing an image may ...

CVEs:CVE-2024-44215

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
tvos affected apple
visionos affected apple
watchos affected apple
Upstream advisory

CVE-2024-44252

visionOSActive exploitation (sightings)HIGH2024-10-28

A logic issue was addressed with improved file handling. This issue is fixed in iOS 17.7.1 and iPadOS 17.7.1, iOS 18.1 and iPadOS 18.1, tvOS 18.1, visionOS 2.1. Restoring a maliciously crafted backup file may lead to modification of protected system fi...

CVEs:CVE-2024-44252

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
tvos affected apple
visionos affected apple
Upstream advisory

CVE-2024-44218

iPadOSActive exploitation (sightings)HIGH2024-10-28

This issue was addressed with improved checks. This issue is fixed in iOS 17.7.1 and iPadOS 17.7.1, iOS 18.1 and iPadOS 18.1, macOS Sequoia 15.1, macOS Sonoma 14.7.1. Processing a maliciously crafted file may lead to heap corruption.

CVEs:CVE-2024-44218

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
Upstream advisory

CVE-2024-44223

macOSActive exploitation (sightings)MEDIUM2024-10-28

This issue was addressed through improved state management. This issue is fixed in macOS Sequoia 15.1. An attacker with physical access to a Mac may be able to view protected content from the Login Window.

CVEs:CVE-2024-44223

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2024-44269

visionOSActive exploitation (sightings)MEDIUM2024-10-28

A logic issue was addressed with improved checks. This issue is fixed in iOS 17.7.1 and iPadOS 17.7.1, iOS 18.1 and iPadOS 18.1, macOS Sequoia 15.1, macOS Sonoma 14.7.1, macOS Ventura 13.7.1, visionOS 2.1, watchOS 11.1. A malicious app may use shortcut...

CVEs:CVE-2024-44269

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
visionos affected apple
watchos affected apple
Upstream advisory

CVE-2024-44159

macOSActive exploitation (sightings)HIGH2024-10-28

A path deletion vulnerability was addressed by preventing vulnerable code from running with privileges. This issue is fixed in macOS Sequoia 15.1, macOS Sonoma 14.7.1, macOS Ventura 13.7.1. An app may be able to bypass Privacy preferences.

CVEs:CVE-2024-44159

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2024-44254

iPadOSActive exploitation (sightings)HIGH2024-10-28

This issue was addressed with improved redaction of sensitive information. This issue is fixed in iOS 18.1 and iPadOS 18.1, macOS Sequoia 15.1, macOS Sonoma 14.7.1, macOS Ventura 13.7.1, watchOS 11.1. An app may be able to access sensitive user data.

CVEs:CVE-2024-44254

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
watchos affected apple
Upstream advisory

CVE-2024-44281

macOSActive exploitation (sightings)MEDIUM2024-10-28

An out-of-bounds read was addressed with improved input validation. This issue is fixed in macOS Sequoia 15.1, macOS Sonoma 14.7.1, macOS Ventura 13.7.1. Parsing a file may lead to disclosure of user information.

CVEs:CVE-2024-44281

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2024-44212

visionOSActive exploitation (sightings)MEDIUM2024-10-28

A cookie management issue was addressed with improved state management. This issue is fixed in Safari 18.1, iOS 18.1 and iPadOS 18.1, macOS Sequoia 15.1, tvOS 18.1, visionOS 2.1, watchOS 11.1. Cookies belonging to one origin may be sent to another origin.

CVEs:CVE-2024-44212

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
safari affected apple
tvos affected apple
visionos affected apple
watchos affected apple
Upstream advisory

CVE-2024-40851

iPadOSActive exploitation (sightings)LOW2024-10-28

This issue was addressed by restricting options offered on a locked device. This issue is fixed in iOS 18.1 and iPadOS 18.1. An attacker with physical access may be able to access contact photos from the lock screen.

CVEs:CVE-2024-40851

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
Upstream advisory

CVE-2024-44278

visionOSActive exploitation (sightings)HIGH2024-10-28

An information disclosure issue was addressed with improved private data redaction for log entries. This issue is fixed in iOS 17.7.1 and iPadOS 17.7.1, iOS 18.1 and iPadOS 18.1, macOS Sequoia 15.1, macOS Sonoma 14.7.1, macOS Ventura 13.7.1, visionOS 2...

CVEs:CVE-2024-44278

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
visionos affected apple
watchos affected apple
Upstream advisory

CVE-2024-44256

macOSActive exploitation (sightings)CRITICAL2024-10-28

The issue was addressed with improved input sanitization. This issue is fixed in macOS Sequoia 15.1, macOS Sonoma 14.7.1, macOS Ventura 13.7.1. An app may be able to break out of its sandbox.

CVEs:CVE-2024-44256

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2024-44260

macOSActive exploitation (sightings)MEDIUM2024-10-28

This issue was addressed by removing the vulnerable code. This issue is fixed in macOS Sequoia 15.1, macOS Sonoma 14.7.1, macOS Ventura 13.7.1. A malicious app with root privileges may be able to modify the contents of system files.

CVEs:CVE-2024-44260

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2024-44216

macOSActive exploitation (sightings)HIGH2024-10-28

An access issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Sequoia 15.1, macOS Sonoma 14.7.1, macOS Ventura 13.7.1. An app may be able to access user-sensitive data.

CVEs:CVE-2024-44216

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2024-44156

macOSActive exploitation (sightings)HIGH2024-10-28

A path deletion vulnerability was addressed by preventing vulnerable code from running with privileges. This issue is fixed in macOS Sequoia 15.1, macOS Sonoma 14.7.1, macOS Ventura 13.7.1. An app may be able to bypass Privacy preferences.

CVEs:CVE-2024-44156

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2024-44280

macOSActive exploitation (sightings)HIGH2024-10-28

A downgrade issue affecting Intel-based Mac computers was addressed with additional code-signing restrictions. This issue is fixed in macOS Sequoia 15.1, macOS Sonoma 14.7.1, macOS Ventura 13.7.1. An app may be able to modify protected parts of the fil...

CVEs:CVE-2024-44280

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2024-44295

macOSActive exploitation (sightings)HIGH2024-10-28

This issue was addressed with additional entitlement checks. This issue is fixed in macOS Sequoia 15.1, macOS Sonoma 14.7.1, macOS Ventura 13.7.1. An app may be able to modify protected parts of the file system.

CVEs:CVE-2024-44295

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2024-44257

macOSActive exploitation (sightings)HIGH2024-10-28

This issue was addressed with improved redaction of sensitive information. This issue is fixed in macOS Sequoia 15.1, macOS Sonoma 14.7.1, macOS Ventura 13.7.1. An app may be able to access sensitive user data.

CVEs:CVE-2024-44257

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2024-40849

macOSActive exploitation (sightings)HIGH2024-10-28

A race condition was addressed with additional validation. This issue is fixed in macOS Sequoia 15.1. An app may be able to break out of its sandbox.

CVEs:CVE-2024-40849

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2024-44287

macOSActive exploitation (sightings)MEDIUM2024-10-28

The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.1, macOS Sonoma 14.7.1, macOS Ventura 13.7.1. A malicious application may be able to modify protected parts of the file system.

CVEs:CVE-2024-44287

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2024-44247

macOSActive exploitation (sightings)MEDIUM2024-10-28

The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.1, macOS Sonoma 14.7.1, macOS Ventura 13.7.1. A malicious application may be able to modify protected parts of the file system.

CVEs:CVE-2024-44247

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2024-54471

macOSActive exploitation (sightings)MEDIUM2024-10-28

This issue was addressed with additional entitlement checks. This issue is fixed in macOS Sequoia 15.1, macOS Sonoma 14.7.1, macOS Ventura 13.7.1. A malicious application may be able to leak a user's credentials.

CVEs:CVE-2024-54471

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2024-44298

macOSActive exploitation (sightings)MEDIUM2024-10-28

A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in macOS Sequoia 15.1. An app may be able to access information about a user's contacts.

CVEs:CVE-2024-44298

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2024-44290

iPadOSActive exploitation (sightings)HIGH2024-10-28

This issue was addressed with improved redaction of sensitive information. This issue is fixed in iOS 18.1 and iPadOS 18.1, macOS Sequoia 15.1, watchOS 11.1. An app may be able to determine a user’s current location.

CVEs:CVE-2024-44290

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
watchos affected apple
Upstream advisory

CVE-2024-44301

macOSActive exploitation (sightings)MEDIUM2024-10-28

The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.1, macOS Sonoma 14.7.1, macOS Ventura 13.7.1. A malicious application may be able to modify protected parts of the file system.

CVEs:CVE-2024-44301

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2024-44292

macOSActive exploitation (sightings)MEDIUM2024-10-28

A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in macOS Sequoia 15.1. An app may be able to access sensitive user data.

CVEs:CVE-2024-44292

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2024-40858

macOSActive exploitation (sightings)HIGH2024-10-28

A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.1. An app may be able to access Contacts without user consent.

CVEs:CVE-2024-40858

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2024-44250

macOSActive exploitation (sightings)CRITICAL2024-10-28

A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.1. An app may be able to execute arbitrary code out of its sandbox or with certain elevated privileges.

CVEs:CVE-2024-44250

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2024-44293

macOSActive exploitation (sightings)MEDIUM2024-10-28

A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in macOS Sequoia 15.1. A user may be able to view sensitive user information.

CVEs:CVE-2024-44293

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2024-44259

visionOSPoC exploitHIGH2024-10-28

This issue was addressed through improved state management. This issue is fixed in Safari 18.1, iOS 17.7.1 and iPadOS 17.7.1, iOS 18.1 and iPadOS 18.1, macOS Sequoia 15.1, visionOS 2.1. An attacker may be able to misuse a trust relationship to download...

CVEs:CVE-2024-44259

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
safari affected apple
visionos affected apple
Upstream advisory

CVE-2024-44244

visionOSPoC exploitCRITICAL2024-10-28

A memory corruption issue was addressed with improved input validation. This issue is fixed in Safari 18.1, iOS 18.1 and iPadOS 18.1, macOS Sequoia 15.1, tvOS 18.1, visionOS 2.1, watchOS 11.1. Processing maliciously crafted web content may lead to an u...

CVEs:CVE-2024-44244

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
safari affected apple
tvos affected apple
visionos affected apple
watchos affected apple
Upstream advisory

CVE-2024-44213

macOSPoC exploitHIGH2024-10-28

An issue existed in the parsing of URLs. This issue was addressed with improved input validation. This issue is fixed in macOS Sequoia 15.1, macOS Sonoma 14.7.1, macOS Ventura 13.7.1. An attacker in a privileged network position may be able to leak sen...

CVEs:CVE-2024-44213

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2024-44229

visionOSPoC exploitHIGH2024-10-28

An information leakage was addressed with additional validation. This issue is fixed in Safari 18.1, iOS 18.1 and iPadOS 18.1, macOS Sequoia 15.1, visionOS 2.1. Private browsing may leak some browsing history.

CVEs:CVE-2024-44229

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
visionos affected apple
Upstream advisory

CVE-2024-44296

visionOSPoC exploitCRITICAL2024-10-28

The issue was addressed with improved checks. This issue is fixed in Safari 18.1, iOS 17.7.1 and iPadOS 17.7.1, iOS 18.1 and iPadOS 18.1, macOS Sequoia 15.1, tvOS 18.1, visionOS 2.1, watchOS 11.1. Processing maliciously crafted web content may prevent ...

CVEs:CVE-2024-44296

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
safari affected apple
tvos affected apple
visionos affected apple
watchos affected apple
Upstream advisory

CVE-2024-44270

macOSPoC exploitHIGH2024-10-28

A logic issue was addressed with improved validation. This issue is fixed in macOS Sequoia 15.1, macOS Sonoma 14.7.1, macOS Ventura 13.7.1. A sandboxed process may be able to circumvent sandbox restrictions.

CVEs:CVE-2024-44270

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2024-44265

macOSPoC exploitHIGH2024-10-28

The issue was addressed by restricting options offered on a locked device. This issue is fixed in macOS Sequoia 15.1, macOS Sonoma 14.7.1, macOS Ventura 13.7.1. An attacker with physical access can input Game Controller events to apps running on a lock...

CVEs:CVE-2024-44265

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2024-44241

iPadOSPoC exploitCRITICAL2024-10-28

The issue was addressed with improved bounds checks. This issue is fixed in iOS 18.1 and iPadOS 18.1, macOS Sequoia 15.1. An attacker may be able to cause unexpected system termination or arbitrary code execution in DCP firmware.

CVEs:CVE-2024-44241

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
Upstream advisory

CVE-2024-44196

macOSPoC exploitHIGH2024-10-28

A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.1, macOS Sonoma 14.7.1, macOS Ventura 13.7.1. An app may be able to modify protected parts of the file system.

CVEs:CVE-2024-44196

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2024-44299

iPadOSPoC exploitCRITICAL2024-10-28

The issue was addressed with improved bounds checks. This issue is fixed in iOS 18.1 and iPadOS 18.1, macOS Sequoia 15.1. An attacker may be able to cause unexpected system termination or arbitrary code execution in DCP firmware.

CVEs:CVE-2024-44299

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
Upstream advisory

CVE-2024-44267

macOSPoC exploitMEDIUM2024-10-28

The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.1, macOS Sonoma 14.7.1, macOS Ventura 13.7.1. A malicious application may be able to modify protected parts of the file system.

CVEs:CVE-2024-44267

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2024-44274

iPadOSPoC exploitMEDIUM2024-10-28

The issue was addressed with improved authentication. This issue is fixed in iOS 17.7.1 and iPadOS 17.7.1, iOS 18.1 and iPadOS 18.1, watchOS 11.1. An attacker with physical access to a locked device may be able to view sensitive user information.

CVEs:CVE-2024-44274

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
watchos affected apple
Upstream advisory

CVE-2024-44219

macOSPoC exploitHIGH2024-10-28

A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.1. A malicious application with root privileges may be able to access private information.

CVEs:CVE-2024-44219

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2024-44286

macOSPoC exploitHIGH2024-10-28

This issue was addressed through improved state management. This issue is fixed in macOS Sequoia 15.1. An attacker with physical access can input keyboard events to apps running on a locked device.

CVEs:CVE-2024-44286

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2024-44255

visionOSPoC exploitHIGH2024-10-28

A path handling issue was addressed with improved logic. This issue is fixed in iOS 18.1 and iPadOS 18.1, macOS Sequoia 15.1, macOS Sonoma 14.7.1, macOS Ventura 13.7.1, tvOS 18.1, visionOS 2.1, watchOS 11.1. A malicious app may be able to run arbitrary...

CVEs:CVE-2024-44255

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
tvos affected apple
visionos affected apple
watchos affected apple
Upstream advisory

CVE-2024-44235

iPadOSPoC exploitMEDIUM2024-10-28

The issue was addressed with improved checks. This issue is fixed in iOS 18.1 and iPadOS 18.1. An attacker may be able to view restricted content from the lock screen.

CVEs:CVE-2024-44235

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
Upstream advisory

CVE-2024-44273

visionOSPoC exploitMEDIUM2024-10-28

This issue was addressed with improved handling of symlinks. This issue is fixed in iOS 18.1 and iPadOS 18.1, macOS Sequoia 15.1, macOS Sonoma 14.7.1, tvOS 18.1, visionOS 2.1, watchOS 11.1. A malicious app may be able to access private information.

CVEs:CVE-2024-44273

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
tvos affected apple
visionos affected apple
watchos affected apple
Upstream advisory

CVE-2024-44201

iPadOSPoC exploitHIGH2024-10-28

The issue was addressed with improved memory handling. This issue is fixed in iOS 18.1 and iPadOS 18.1, iPadOS 17.7.3, macOS Sequoia 15.1, macOS Sonoma 14.7.2, macOS Ventura 13.7.2. Processing a malicious crafted file may lead to a denial-of-service.

CVEs:CVE-2024-44201

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
Upstream advisory

CVE-2024-44303

macOSPoC exploitHIGH2024-10-28

The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.1. A malicious application may be able to modify protected parts of the file system.

CVEs:CVE-2024-44303

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2024-44239

iPadOSPoC exploitHIGH2024-10-28

An information disclosure issue was addressed with improved private data redaction for log entries. This issue is fixed in iOS 17.7.1 and iPadOS 17.7.1, iOS 18.1 and iPadOS 18.1, macOS Sequoia 15.1, macOS Sonoma 14.7.1, macOS Ventura 13.7.1, tvOS 18.1,...

CVEs:CVE-2024-44239

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
tvos affected apple
visionos affected apple
watchos affected apple
Upstream advisory

CVE-2024-44251

iPadOSPoC exploitLOW2024-10-28

This issue was addressed through improved state management. This issue is fixed in iOS 18.1 and iPadOS 18.1. An attacker may be able to view restricted content from the lock screen.

CVEs:CVE-2024-44251

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
Upstream advisory

CVE-2024-44194

visionOSPoC exploitHIGH2024-10-28

This issue was addressed with improved redaction of sensitive information. This issue is fixed in iOS 18.1 and iPadOS 18.1, macOS Sequoia 15.1, visionOS 2.1, watchOS 11.1. An app may be able to access sensitive user data.

CVEs:CVE-2024-44194

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
visionos affected apple
watchos affected apple
Upstream advisory

CVE-2024-44222

macOSPoC exploitHIGH2024-10-28

This issue was addressed with improved redaction of sensitive information. This issue is fixed in macOS Sequoia 15.1, macOS Sonoma 14.7.1, macOS Ventura 13.7.1. An app may be able to read sensitive location information.

CVEs:CVE-2024-44222

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2024-44262

visionOSPoC exploitHIGH2024-10-28

This issue was addressed with improved redaction of sensitive information. This issue is fixed in visionOS 2.1. A user may be able to view sensitive user information.

CVEs:CVE-2024-44262

Affected products

ProductStatusVendorPackageEcosystem
visionos affected apple
Upstream advisory

CVE-2024-44277

visionOSPoC exploitHIGH2024-10-28

The issue was addressed with improved memory handling. This issue is fixed in iOS 18.1 and iPadOS 18.1, macOS Sequoia 15.1, tvOS 18.1, visionOS 2.1. An app may be able to cause unexpected system termination or corrupt kernel memory.

CVEs:CVE-2024-44277

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
tvos affected apple
visionos affected apple
Upstream advisory

CVE-2024-44261

iPadOSPoC exploitMEDIUM2024-10-28

This issue was addressed by restricting options offered on a locked device. This issue is fixed in iOS 17.7.1 and iPadOS 17.7.1, iOS 18.1 and iPadOS 18.1. An attacker may be able to view restricted content from the lock screen.

CVEs:CVE-2024-44261

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
Upstream advisory

CVE-2024-44275

macOSPoC exploitMEDIUM2024-10-28

The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.1, macOS Sonoma 14.7.1, macOS Ventura 13.7.1. A malicious application may be able to modify protected parts of the file system.

CVEs:CVE-2024-44275

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2024-44253

macOSPoC exploitMEDIUM2024-10-28

The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.1, macOS Sonoma 14.7.1, macOS Ventura 13.7.1. An app may be able to modify protected parts of the file system.

CVEs:CVE-2024-44253

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2024-44263

iPadOSPoC exploitHIGH2024-10-28

A logic issue was addressed with improved state management. This issue is fixed in iOS 18.1 and iPadOS 18.1. An app may be able to access user-sensitive data.

CVEs:CVE-2024-44263

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
Upstream advisory

CVE-2024-44200

iPadOSPoC exploitHIGH2024-10-28

This issue was addressed with improved redaction of sensitive information. This issue is fixed in iOS 18.1 and iPadOS 18.1, macOS Sequoia 15.1. An app may be able to read sensitive location information.

CVEs:CVE-2024-44200

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
Upstream advisory

CVE-2024-54554

macOSPoC exploitMEDIUM2024-10-28

This issue was addressed with improved handling of symlinks. This issue is fixed in macOS Sequoia 15.1. An app may be able to access sensitive user data.

CVEs:CVE-2024-54554

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

Need live exploit intelligence?

Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.