First published: Mon Oct 28 2024(Updated: )
A path handling issue was addressed with improved logic. This issue is fixed in visionOS 2.1, iOS 18.1 and iPadOS 18.1, macOS Ventura 13.7.1, macOS Sonoma 14.7.1, watchOS 11.1, tvOS 18.1. A malicious app may be able to run arbitrary shortcuts without user consent.
Credit: Rizki Maulana (rmrizki.my.id) Matthew Butler Jake Derouin an anonymous researcher Ivan Fratric Google Project ZeroK宝 @Pwnrin pattern-f @pattern_F_ Loadshine LabHikerell Loadshine LabHossein Lotfi @hosselot Trend Micro Zero Day InitiativeWang Yu CyberservalJunsung Lee Trend Micro Zero Day InitiativeJex Amro Ye Zhang @VAR10CK Baidu SecurityZiyi Zhou Jiao Tong University) @Shanghai Tianxiao Hou Jiao Tong University) @Shanghai Mateusz Krzywicki @krzywix Ben Roeder Hichem Maloufi Christian Mina Ismail Amzdak Nimrat Khalsa Davis Dai James Gill @infosec.exchange) @jjtech an anonymous researcher Dawn Security Lab of JDYinyi Wu @_3ndy1 Dawn Security Lab of JDNarendra Bhati Cyber Security at Suma Soft PvtManager Cyber Security at Suma Soft PvtPune (India) Lucas Di Tomase Michael DePlante @izobashi Trend Micro Zero Day InitiativeBing Shi Alibaba GroupWenchao Li Alibaba GroupXiaolong Bai Alibaba Group Indiana University BloomingtonLuyi Xing Indiana University BloomingtonKirin @Pwnrin Bistrit Dahal Kenneth Chew Rodolphe Brunetti @eisw0lf Abhay Kailasia @abhay_kailasia Lakshmi Narain College of Technology Bhopal IndiaSrijan Poudel 7feilee Cristian Dinca (icmd.tech) Dalibor Milanovic Richard Hyunho Im with Route Zero Security @richeeta Braylon @softwarescool Wojciech Regula SecuRingQ1IQ @q1iqF P1umer @p1umer CVE-2024-39573 CVE-2024-38477 CVE-2024-38476 Mickey Jin @patch1t Alexandre Bedard Ronny Stiftel Zhongquan Li @Guluisacat Garrett Moon Excited Pixel LLCArsenii Kostromin (0x3c3e) Toomas Römer Jaime Bertran Noah Gregory (wts.dev) Un3xploitable CW Research IncBohdan Stasiuk @Bohdan_Stasiuk CW Research IncPedro Tôrres @t0rr3sp3dr0 Mickey Jin @patch1t KandjiCsaba Fitzl @theevilbit KandjiRyan Dowd @_rdowd Gergely Kalman @gergely_kalman Csaba Fitzl @theevilbit Halle Winkler Politepix (theoffcuts.org) dw0r! Trend Micro Zero Day InitiativeBohdan Stasiuk @Bohdan_Stasiuk Holger Fuhrmannek Politepix @hallewinkler Justin Saboo 냥냥 product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
Apple macOS | <13.7.1 | 13.7.1 |
Apple visionOS | <2.1 | 2.1 |
Apple macOS | <14.7.1 | 14.7.1 |
tvOS | <18.1 | 18.1 |
watchOS | <11.1 | 11.1 |
Apple macOS Sequoia | <15.1 | 15.1 |
Apple iOS | <18.1 | 18.1 |
iPadOS | <18.1 | 18.1 |
iPadOS | <18.1 | |
Apple iPhone OS | <18.1 | |
Apple macOS | <13.7.1 | |
Apple macOS | >=14.0<14.7.1 | |
tvOS | <18.1 | |
Apple visionOS | <2.1 | |
watchOS | <11.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Appears in the following advisories)
(Found alongside the following vulnerabilities)
CVE-2024-44255 is considered a medium severity vulnerability due to the potential for a malicious app to execute shortcuts without user consent.
To fix CVE-2024-44255, update your device to the latest versions: visionOS 2.1, iOS 18.1, iPadOS 18.1, macOS Ventura 13.7.1, macOS Sonoma 14.7.1, watchOS 11.1, or tvOS 18.1.
CVE-2024-44255 affects various Apple devices including iPhones, iPads, Macs, Apple Watches, and Apple TVs running specified versions of their operating systems.
Exploiting CVE-2024-44255 allows a malicious app to run arbitrary shortcuts without the user's consent, potentially leading to unauthorized actions.
Currently, there is no recommended workaround for CVE-2024-44255 other than applying the necessary updates provided by Apple.