VulnerabilityModified
CVE-2024-54507
An attacker with user privileges may be able to read kernel memory.
MEDIUM 5.5EPSS 0.89%
Does this matter?
Lower severity and a low EPSS score (0.89%). Track it; it rarely justifies an emergency change on its own.
Description
A type confusion issue was addressed with improved memory handling. This issue is fixed in iOS 18.2 and iPadOS 18.2, macOS Sequoia 15.2. An attacker with user privileges may be able to read kernel memory.
- CVSS 3.1
- 5.5 MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 0.89% probability · 57th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-843, CWE-125
- Affected
- apple/ipados · apple/iphone os · apple/macos
- Source
- product-security@apple.com
References
- https://support.apple.com/en-us/121837Release Notes, Vendor Advisory
- https://support.apple.com/en-us/121839Release Notes, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.