First published: Mon May 13 2024(Updated: )
Apple Neural Engine. The issue was addressed with improved memory handling.
Credit: Minghao Lin Baidu Security Baidu SecurityYe Zhang @VAR10CK Baidu SecurityMeysam Firouzi @R00tkitSMM Mickey Jin @patch1t an anonymous researcher Kirin @Pwnrin 小来来 @Smi1eSEC CertiK SkyFall Team Pan ZhenPeng @Peterpan0927 STAR Labs SG Ptean anonymous researcher MIT CSAIL MIT CSAILJoseph Ravichandran @0xjprx MIT CSAILPr BarPr Hebrew University EP Nick Wellnhofer Gil Pedersen Dohyun Lee @l33d0hyun LFY @secsys Fudan UniversityDaniel Zajork Joshua Zajork Dalibor Milanovic Csaba Fitzl @theevilbit KandjiLFY @secsys yulige Snoolie Keffaber @0xilis Robert Reichel CVE-2024-27806 Maksymilian Motyl Immunity SystemsJunsung Lee Trend Micro Zero Day Initiativeajajfxhj Manfred Paul @_manfp Trend Micro's Zero Day InitiativeEmilio Cobos MozillaLukas Bernhard CISPA Helmholtz Center for Information SecurityNan Wang @eternalsakura13 360 Vulnerability Research InstituteJoe Rutkowski @Joe12387 Crawless @abrahamjuliot Jeff Johnson underpassapp product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
Apple iOS, iPadOS, and watchOS | <10.5 | 10.5 |
Apple iOS, iPadOS, and watchOS | <10.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2024-27814 has been rated as a high severity vulnerability due to its potential impact on the systems affected.
To fix CVE-2024-27814, update your Apple watchOS to version 10.5 or later.
CVE-2024-27814 affects versions of watchOS prior to 10.5.
CVE-2024-27814 involves improved memory handling and validation of environment variables.
Yes, CVE-2024-27814 specifically affects Apple watchOS versions up to 10.5.