Buffer overflow in macOS - CVE-2024-54518
Published: March 18, 2025 / Updated: March 18, 2025
Vulnerability identifier: #VU105813
CSH Severity: Low
CVSS v4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-54518
CWE-ID: CWE-119
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local application to escalate privileges on the system.
The vulnerability exists due to a boundary error in IOMobileFrameBuffer. A local application can trigger memory corruption and execute arbitrary code on the target system.
Affected software
macOS
watchOS
tvOS
iPadOS
Apple iOS
watchOS
tvOS
iPadOS
Apple iOS
How to mitigate CVE-2024-54518
Install updates from vendor's website.
macOS - update to 15.2 24C101
watchOS - update to 11.2
tvOS - update to 18.2
iPadOS - update to 18.2 22C152
Apple iOS - update to 18.2 22C152
watchOS - update to 11.2
tvOS - update to 18.2
iPadOS - update to 18.2 22C152
Apple iOS - update to 18.2 22C152