First published: Mon Oct 28 2024(Updated: )
Accessibility. The issue was addressed with improved authentication.
Credit: product-security@apple.com Narendra Bhati Cyber Security at Suma Soft PvtManager Cyber Security at Suma Soft PvtPune (India) Lucas Di Tomase Michael DePlante @izobashi Trend Micro Zero Day InitiativeBing Shi Alibaba GroupWenchao Li Alibaba GroupXiaolong Bai Alibaba Group Indiana University BloomingtonLuyi Xing Indiana University BloomingtonKirin @Pwnrin an anonymous researcher Bistrit Dahal Kenneth Chew Rodolphe Brunetti @eisw0lf Abhay Kailasia @abhay_kailasia Lakshmi Narain College of Technology Bhopal IndiaSrijan Poudel 7feilee Cristian Dinca (icmd.tech) Rizki Maulana (rmrizki.my.id) Dalibor Milanovic Richard Hyunho Im with Route Zero Security @richeeta Braylon @softwarescool Wojciech Regula SecuRingQ1IQ @q1iqF P1umer @p1umer Jex Amro Ye Zhang @VAR10CK Baidu SecurityZiyi Zhou Jiao Tong University) @Shanghai Tianxiao Hou Jiao Tong University) @Shanghai Mateusz Krzywicki @krzywix Ben Roeder Hichem Maloufi Christian Mina Ismail Amzdak Nimrat Khalsa Davis Dai James Gill @infosec.exchange) @jjtech an anonymous researcher Dawn Security Lab of JDYinyi Wu @_3ndy1 Dawn Security Lab of JDHossein Lotfi @hosselot Trend Micro Zero Day InitiativeWang Yu CyberservalJunsung Lee Trend Micro Zero Day Initiativepattern-f @pattern_F_ Loadshine LabHikerell Loadshine LabIvan Fratric Google Project ZeroK宝 @Pwnrin Matthew Butler Jake Derouin
Affected Software | Affected Version | How to fix |
---|---|---|
Apple iOS | <18.1 | 18.1 |
iPadOS | <18.1 | 18.1 |
iPadOS | <18.1 | |
Apple iPhone OS | <18.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2024-44235 has been assessed with a high severity level due to its potential impact on user security and system integrity.
To mitigate CVE-2024-44235, users should update their Apple iOS and iPadOS devices to version 18.1 or later immediately.
CVE-2024-44235 affects devices running Apple iOS and iPadOS versions prior to 18.1.
CVE-2024-44235 addresses several issues including improved authentication, path handling, and bounds checks.
As of the latest updates, there is no public information indicating that CVE-2024-44235 is currently being exploited in the wild.