VulnerabilityModified
CVE-2024-44198
An integer overflow was addressed through improved input validation.
MEDIUM 5.5EPSS 0.19%
Does this matter?
Lower severity and a low EPSS score (0.19%). Track it; it rarely justifies an emergency change on its own.
Description
An integer overflow was addressed through improved input validation. This issue is fixed in iOS 18 and iPadOS 18, macOS Sequoia 15, tvOS 18, visionOS 2, watchOS 11. Processing maliciously crafted web content may lead to an unexpected process crash.
- CVSS 3.1
- 5.5 MEDIUMCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
- EPSS
- 0.19% probability · 8th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-190
- Affected
- apple/ipados · apple/iphone os · apple/macos · apple/tvos · apple/visionos · apple/watchos
- Source
- product-security@apple.com
References
- https://support.apple.com/en-us/121238Release Notes, Vendor Advisory
- https://support.apple.com/en-us/121240Release Notes, Vendor Advisory
- https://support.apple.com/en-us/121248Release Notes, Vendor Advisory
- https://support.apple.com/en-us/121249Release Notes, Vendor Advisory
- https://support.apple.com/en-us/121250Release Notes, Vendor Advisory
- http://seclists.org/fulldisclosure/2024/Sep/32
- http://seclists.org/fulldisclosure/2024/Sep/33
- http://seclists.org/fulldisclosure/2024/Sep/36
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.