#VU95293 Buffer overflow in macOS - CVE-2024-27857
Published: August 5, 2024 / Updated: August 26, 2024
macOS
Apple Inc.
Description
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to a boundary error in Metal. A remote attacker can create a specially crafted KTX file, trick the victim into opening it, trigger memory corruption and execute arbitrary code on the target system.
Remediation
External links
- https://support.apple.com/en-us/HT214106
- https://www.zerodayinitiative.com/advisories/ZDI-24-1119/
- https://www.zerodayinitiative.com/advisories/ZDI-24-1118/
- https://www.zerodayinitiative.com/advisories/ZDI-24-1117/
- https://www.zerodayinitiative.com/advisories/ZDI-24-1116/
- https://www.zerodayinitiative.com/advisories/ZDI-24-1115/
- https://www.zerodayinitiative.com/advisories/ZDI-24-1114/
- https://www.zerodayinitiative.com/advisories/ZDI-24-1113/
- https://www.zerodayinitiative.com/advisories/ZDI-24-1112/
- https://www.zerodayinitiative.com/advisories/ZDI-24-1111/
- https://www.zerodayinitiative.com/advisories/ZDI-24-1110/
- https://www.zerodayinitiative.com/advisories/ZDI-24-1109/
- https://www.zerodayinitiative.com/advisories/ZDI-24-1108/
- https://www.zerodayinitiative.com/advisories/ZDI-24-1107/
- https://www.zerodayinitiative.com/advisories/ZDI-24-1180/
- https://www.zerodayinitiative.com/advisories/ZDI-24-1179/