VulnerabilityModified
CVE-2024-54505
Processing maliciously crafted web content may lead to memory corruption.
HIGH 8.8EPSS 1.09%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.09%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
A type confusion issue was addressed with improved memory handling. This issue is fixed in Safari 18.2, iOS 18.2 and iPadOS 18.2, iPadOS 17.7.3, macOS Sequoia 15.2, tvOS 18.2, visionOS 2.2, watchOS 11.2. Processing maliciously crafted web content may lead to memory corruption.
- CVSS 3.1
- 8.8 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
- EPSS
- 1.09% probability · 63th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-843
- Affected
- apple/safari · apple/ipados · apple/iphone os · apple/macos · apple/tvos · apple/visionos · apple/watchos
- Source
- product-security@apple.com
References
- https://support.apple.com/en-us/121837Vendor Advisory
- https://support.apple.com/en-us/121838Vendor Advisory
- https://support.apple.com/en-us/121839Vendor Advisory
- https://support.apple.com/en-us/121843Vendor Advisory
- https://support.apple.com/en-us/121844Vendor Advisory
- https://support.apple.com/en-us/121845Vendor Advisory
- https://support.apple.com/en-us/121846Vendor Advisory
- http://seclists.org/fulldisclosure/2024/Dec/10
- http://seclists.org/fulldisclosure/2024/Dec/13
- http://seclists.org/fulldisclosure/2024/Dec/6
- http://seclists.org/fulldisclosure/2024/Dec/7
- https://lists.debian.org/debian-lts-announce/2025/01/msg00002.html
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.