CVE-2024-54540: XSS
Published Oct 3, 2024
·Updated
Music. The issue was addressed with improved input sanitization.
Other sources
The issue was addressed with improved input sanitization. This issue is fixed in Apple Music 1.5.0.152 for Windows. Processing maliciously crafted web content may disclose internal states of the app.
— NVD
Credit
Dominik Penner (zer0pwn)
Affected Software
6 affected componentsFixes available
Apple Apple Music for Windows<1.5.0.152
1.5.0.152
Apple Music<1.5.0.152
All of the following
Apple Music<1.5.0.152
Any of the following
Microsoft Windows 10 22h2
Microsoft Windows 10 22h2
Microsoft Windows 11 24h2
Event History
Jan 15, 2025
CVE Published
via MITRE·07:35 PM
Data Sourced
via MITRE·07:35 PM
DescriptionWeakness
Data Sourced
via NVD·08:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-54540?
CVE-2024-54540 is considered a high-severity vulnerability due to its potential to disclose internal states of the Apple Music application.
2
How do I fix CVE-2024-54540?
To fix CVE-2024-54540, update Apple Music for Windows to version 1.5.0.152 or later.
3
What platforms are affected by CVE-2024-54540?
CVE-2024-54540 affects Apple Music for Windows versions prior to 1.5.0.152.
4
What type of issue is reported in CVE-2024-54540?
CVE-2024-54540 is a security vulnerability related to improper input sanitization.
5
Can CVE-2024-54540 be exploited remotely?
Yes, CVE-2024-54540 may be exploited through maliciously crafted web content.