Heap-based buffer overflow in macOS - CVE-2024-44126

 

Heap-based buffer overflow in macOS - CVE-2024-44126

Published: October 28, 2024


Vulnerability identifier: #VU99362
CSH Severity: High
CVSS v4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-44126
CWE-ID: CWE-122
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to compromise the affected system.

The vulnerability exists due to a boundary error in ARKit. A remote attacker can trick the victim into opening a specially crafted file, trigger a heap-based buffer overflow and execute arbitrary code on the target system.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.


Affected software

macOS
visionOS
iPadOS
Apple iOS

How to mitigate CVE-2024-44126

Install updates from vendor's website.

macOS - addressed in versions 13.7.1 22H221, 14.7 23H124, 15.0 24A335
visionOS - update to 2.0
iPadOS - addressed in versions 17.7 21H16, 18.0 22A3354
Apple iOS - update to 18.0 22A3354

External References

Related Security Bulletins