A race condition was addressed with additional validation. This issue is fixed in macOS Ventura 13.6.8, iOS 17.6 and iPadOS 17.6, watchOS 10.6, tvOS 17.6, macOS Sonoma 14.6. A malicious attacker with arbitrary read and write capability may be able to bypass Pointer Authentication.
Metrics
Affected Vendors & Products
References
History
Thu, 15 Aug 2024 16:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Apple
Apple ipados Apple iphone Os Apple macos Apple tvos Apple watchos |
|
Weaknesses | CWE-362 | |
CPEs | cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:* cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:* cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:* cpe:2.3:o:apple:tvos:*:*:*:*:*:*:*:* cpe:2.3:o:apple:watchos:*:*:*:*:*:*:*:* |
|
Vendors & Products |
Apple
Apple ipados Apple iphone Os Apple macos Apple tvos Apple watchos |
|
Metrics |
cvssV3_1
|
MITRE
Status: PUBLISHED
Assigner: apple
Published: 2024-07-29T22:17:07.016Z
Updated: 2024-08-02T04:39:54.860Z
Reserved: 2024-07-10T17:11:04.696Z
Link: CVE-2024-40815
Vulnrichment
Updated: 2024-08-02T04:39:54.860Z
NVD
Status : Modified
Published: 2024-07-29T23:15:13.523
Modified: 2024-11-21T09:31:41.690
Link: CVE-2024-40815
Redhat
No data.