VDB

CVE-2024-54540

CVE-2024-54540 PUBLISHED CVSS 5.5 MEDIUM

The issue was addressed with improved input sanitization. This issue is fixed in Apple Music 1.5.0.152 for Windows. Processing maliciously crafted web content may disclose internal states of the app.

EPSS 0.21% · 10.2th percentile

Risk Scores

CVSS 3.1
5.5
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
EPSS Score
0.21%
10.2th percentile

Affected Products

VendorProductVersions
AppleApple Music0
applemusic0, 0
AppleApple Music for Windowsunspecified

Timeline

  • Jan 14, 2025 PoC Published
  • Jan 15, 2025 CVE Published
  • Jan 15, 2025 PoC Published
  • Jan 15, 2025 PoC Published
  • Jan 15, 2025 PoC Published
  • Jan 15, 2025 PoC Published
  • Jan 15, 2025 PoC Published
  • Jan 16, 2025 EPSS Score
  • Feb 1, 2025 EPSS Score
  • Feb 17, 2025 EPSS Score
  • Feb 18, 2025 Coalition ESS Score
  • Mar 4, 2025 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›