VDB
CVE-2024-54540
CVE-2024-54540
PUBLISHED
CVSS 5.5 MEDIUM
The issue was addressed with improved input sanitization. This issue is fixed in Apple Music 1.5.0.152 for Windows. Processing maliciously crafted web content may disclose internal states of the app.
EPSS 0.21% · 10.2th percentile
Risk Scores
CVSS 3.1
5.5
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
EPSS Score
0.21%
10.2th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Apple | Apple Music | 0 |
| apple | music | 0, 0 |
| Apple | Apple Music for Windows | unspecified |
Timeline
- Jan 14, 2025 PoC Published
- Jan 15, 2025 CVE Published
- Jan 15, 2025 PoC Published
- Jan 15, 2025 PoC Published
- Jan 15, 2025 PoC Published
- Jan 15, 2025 PoC Published
- Jan 15, 2025 PoC Published
- Jan 16, 2025 EPSS Score
- Feb 1, 2025 EPSS Score
- Feb 17, 2025 EPSS Score
- Feb 18, 2025 Coalition ESS Score
- Mar 4, 2025 EPSS Score