Heap-based buffer overflow in macOS - CVE-2024-44126
Published: October 28, 2024
Vulnerability details
The vulnerability allows a remote attacker to compromise the affected system.
The vulnerability exists due to a boundary error in ARKit. A remote attacker can trick the victim into opening a specially crafted file, trigger a heap-based buffer overflow and execute arbitrary code on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
Affected software
visionOS
iPadOS
Apple iOS
How to mitigate CVE-2024-44126
visionOS - update to 2.0
iPadOS - addressed in versions 17.7 21H16, 18.0 22A3354
Apple iOS - update to 18.0 22A3354