First published: Mon May 13 2024(Updated: )
Apple Neural Engine. The issue was addressed with improved memory handling.
Credit: product-security@apple.com Amir Bazine CrowdStrike Counter Adversary OperationsKarsten König CrowdStrike Counter Adversary OperationsPwn2car Trend Micro's Zero Day Initiative Trend Micro's Zero Day InitiativeMichael DePlante @izobashi Trend Micro's Zero Day InitiativeMickey Jin @patch1t Narendra Bhati Suma Soft PvtShaheen Fazim Csaba Fitzl @theevilbit KandjiKirin @Pwnrin LFY @secsys 小来来 @Smi1eSEC yulige Snoolie Keffaber @0xilis Robert Reichel an anonymous researcher CVE-2024-27806 Yann GASCUEL Alter SolutionsCertiK SkyFall Team ajajfxhj Maksymilian Motyl Immunity SystemsJunsung Lee Trend Micro Zero Day InitiativeManfred Paul @_manfp Trend Micro's Zero Day InitiativeEmilio Cobos MozillaLukas Bernhard CISPA Helmholtz Center for Information SecurityNan Wang @eternalsakura13 360 Vulnerability Research InstituteJoe Rutkowski @Joe12387 Crawless @abrahamjuliot Jeff Johnson underpassappRon Masas Impervapattern-f @pattern_F_ Ant Security Lightan anonymous researcher MIT CSAIL MIT CSAILJoseph Ravichandran @0xjprx MIT CSAILPr BarPr Hebrew UniversityEP Nick Wellnhofer Gil Pedersen Dohyun Lee @l33d0hyun LFY @secsys Fudan UniversityDaniel Zajork Joshua Zajork Meysam Firouzi @R00tkitsmm Trend Micro Zero Day InitiativeMichael DePlante @izobashi Trend Micro Zero Day InitiativeScott Johnson RIPEDA ConsultingMykola Grymalyuk RIPEDA ConsultingJordy Witteman Carlos Polop Pedro Tôrres @t0rr3sp3dr0 Minghao Lin Baidu Security Baidu SecurityYe Zhang @VAR10CK Baidu SecurityMeysam Firouzi @R00tkitSMM
Affected Software | Affected Version | How to fix |
---|---|---|
Apple macOS | >=14.0<14.5 | |
Apple macOS | <14.5 | 14.5 |
<14.5 | 14.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2024-27829 is classified as a high severity vulnerability because it may lead to unexpected app termination or arbitrary code execution.
To fix CVE-2024-27829, users should update to macOS Sonoma version 14.5 or later.
CVE-2024-27829 affects macOS versions prior to 14.5.
CVE-2024-27829 exploits improved memory handling, allowing for potential app crashes or arbitrary code execution.
There are no known workarounds for CVE-2024-27829; applying the latest updates is recommended.