Race condition in visionOS - CVE-2024-27823
Published: July 30, 2024 / Updated: August 5, 2024
Vulnerability identifier: #VU94918
CSH Severity: Low
CVSS v4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-27823
CWE-ID: CWE-362
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to a race condition. A local user can exploit the race and gain unauthorized access to sensitive information and escalate privileges on the system.
Affected software
visionOS
watchOS
macOS
Apple iOS
iPadOS
tvOS
watchOS
macOS
Apple iOS
iPadOS
tvOS
How to mitigate CVE-2024-27823
Install updates from vendor's website.
visionOS - update to 1.3
watchOS - update to 10.5
macOS - addressed in versions 12.7.5 21H1222, 13.6.7 22G720, 14.5 23F79
Apple iOS - addressed in versions 16.7.8 20H343, 17.5 21F79
iPadOS - addressed in versions 16.7.8, 17.5 21F79
tvOS - update to 17.5
watchOS - update to 10.5
macOS - addressed in versions 12.7.5 21H1222, 13.6.7 22G720, 14.5 23F79
Apple iOS - addressed in versions 16.7.8 20H343, 17.5 21F79
iPadOS - addressed in versions 16.7.8, 17.5 21F79
tvOS - update to 17.5
External References
Related Security Bulletins
- Multiple vulnerabilities in Apple visionOS
- Multiple vulnerabilities in Apple macOS Sonoma
- Multiple vulnerabilities in Apple macOS Ventura
- Multiple vulnerabilities in Apple macOS Monterey
- Multiple vulnerabilities in Apple iOS 16 and iPadOS 16
- Multiple vulnerabilities in Apple iOS 17 and iPadOS 17
- Multiple vulnerabilities in Apple tvOS
- Multiple vulnerabilities in Apple watchOS