Integer overflow in macOS - CVE-2024-40784
Published: July 30, 2024 / Updated: October 3, 2024
Vulnerability identifier: #VU94869
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-40784
CWE-ID: CWE-190
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to integer overflow in ImageIO. A remote attacker can trick the victim to open a specially crafted image file, trigger an integer overflow and crash the application.
Affected software
macOS
visionOS
watchOS
Apple iOS
iPadOS
tvOS
visionOS
watchOS
Apple iOS
iPadOS
tvOS
How to mitigate CVE-2024-40784
Install updates from vendor's website.
macOS - addressed in versions 14.6 23G80, 13.6.8 22G820
visionOS - update to 1.3
watchOS - update to 10.6
Apple iOS - addressed in versions 16.7.9 20H348, 17.6 21G80
iPadOS - addressed in versions 16.7.9 20H348, 17.6 21G80
tvOS - update to 17.6
visionOS - update to 1.3
watchOS - update to 10.6
Apple iOS - addressed in versions 16.7.9 20H348, 17.6 21G80
iPadOS - addressed in versions 16.7.9 20H348, 17.6 21G80
tvOS - update to 17.6
External References
Related Security Bulletins
- Multiple vulnerabilities in Apple macOS Sonoma
- Multiple vulnerabilities in Apple macOS Ventura
- Multiple vulnerabilities in Apple iOS 17 and iPadOS 17
- Multiple vulnerabilities in Apple iOS 16 and iPadOS 16
- Multiple vulnerabilities in Apple tvOS
- Multiple vulnerabilities in Apple watchOS
- Multiple vulnerabilities in Apple visionOS