VDB
CVE-2024-54486
CVE-2024-54486
PUBLISHED
CVSS 8.699999809265137 HIGH
Das Apple iOS (vormals iPhone OS) ist das Betriebssystem für das von Apple entwickelte Smartphone iPhone, iPad und iPod Touch. Das Apple iPadOS ist das Betriebssystem für das von Apple entwickelte iPad.
EPSS 1.39% · 70.2th percentile
Risk Scores
CVSS 4.0
8.699999809265137
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
EPSS Score
1.39%
70.2th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Apple | Apple macOS <14.7.2 | |
| Apple | Apple macOS <13.7.2 | |
| Apple | Apple iPadOS <17.7.3 | |
| Apple | Apple iOS <18.2 | |
| Apple | Apple macOS <15.2 | |
| Apple | Apple iPadOS <18.2 |
Timeline
- Dec 11, 2024 CVE Published
- Dec 11, 2024 PoC Published
- Dec 12, 2024 EPSS Score
- Dec 27, 2024 Coalition ESS Score
- Dec 29, 2024 EPSS Score
- Jan 15, 2025 EPSS Score
- Jan 31, 2025 EPSS Score
- Feb 17, 2025 EPSS Score
- Mar 6, 2025 EPSS Score
- Mar 8, 2025 Coalition ESS Score
- Mar 18, 2025 PoC Published
- Mar 23, 2025 EPSS Score
References
- https://wid.cert-bund.de/.well-known/csaf/white/2024/wid-sec-w-2024-3692.json advisory
- https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2024-3692 advisory
- https://lists.apple.com/archives/security-announce/2024/Dec/msg00002.html advisory
- https://lists.apple.com/archives/security-announce/2024/Dec/msg00003.html advisory
- https://lists.apple.com/archives/security-announce/2024/Dec/msg00004.html advisory
- https://jhftss.github.io/CVE-2024-54527-MediaLibraryService-Full-TCC-Bypass/ advisory
- https://cybersecuritynews.com/macos-sandbox-vulnerability-cve-2024-54498-poc-exploit-released/ exploit
- https://github.com/koreacsl/SysBumps advisory
- https://wid.cert-bund.de/.well-known/csaf/white/2024/wid-sec-w-2024-3691.json advisory
- https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2024-3691 advisory
- https://lists.apple.com/archives/security-announce/2024/Dec/msg00000.html advisory
- https://lists.apple.com/archives/security-announce/2024/Dec/msg00001.html advisory