Integer overflow in macOS - CVE-2024-44198

 

Integer overflow in macOS - CVE-2024-44198

Published: September 17, 2024


Vulnerability identifier: #VU97385
CSH Severity: High
CVSS v4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-44198
CWE-ID: CWE-190
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to integer overflow in libxml2. A remote attacker can pass specially crafted data to the application, trigger an integer overflow and execute arbitrary code on the target system.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.


Affected software

macOS
visionOS
watchOS
tvOS
Apple iOS
iPadOS

How to mitigate CVE-2024-44198

Install updates from vendor's website.

macOS - update to 15.0 24A335
visionOS - update to 2.0
watchOS - update to 11.0
tvOS - update to 18.0
Apple iOS - update to 18.0 22A3354
iPadOS - update to 18.0 22A3354

External References

Related Security Bulletins