VulnerabilityModified
CVE-2024-54534
Processing maliciously crafted web content may lead to memory corruption.
CRITICAL 9.8EPSS 1.05%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.05%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
The issue was addressed with improved memory handling. This issue is fixed in Safari 18.2, iOS 18.2 and iPadOS 18.2, iPadOS 17.7.6, macOS Sequoia 15.2, tvOS 18.2, visionOS 2.2, watchOS 11.2. Processing maliciously crafted web content may lead to memory corruption.
- CVSS 3.1
- 9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 1.05% probability · 62th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-787
- Affected
- apple/safari · apple/ipados · apple/iphone os · apple/macos · apple/tvos · apple/visionos · apple/watchos
- Source
- product-security@apple.com
References
- https://support.apple.com/en-us/121837Vendor Advisory
- https://support.apple.com/en-us/121839Vendor Advisory
- https://support.apple.com/en-us/121843Vendor Advisory
- https://support.apple.com/en-us/121844Vendor Advisory
- https://support.apple.com/en-us/121845Vendor Advisory
- https://support.apple.com/en-us/121846Vendor Advisory
- https://support.apple.com/en-us/122372
- http://seclists.org/fulldisclosure/2024/Dec/11
- http://seclists.org/fulldisclosure/2024/Dec/13
- http://seclists.org/fulldisclosure/2024/Dec/5
- http://seclists.org/fulldisclosure/2024/Dec/7
- http://seclists.org/fulldisclosure/2025/Apr/5
- https://security.netapp.com/advisory/ntap-20250418-0002/
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.