This issue was addressed by removing the vulnerable code. This issue is fixed in macOS Ventura 13.7, visionOS 2, iOS 18 and iPadOS 18, macOS Sonoma 14.7, macOS Sequoia 15. An app may be able to overwrite arbitrary files.
History

Wed, 18 Sep 2024 08:30:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple ios And Ipados
Apple visionos
Mercurycom
Mercurycom mac1200r Firmware
Weaknesses CWE-22
CPEs cpe:2.3:o:apple:ios_and_ipados:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:visionos:-:*:*:*:*:*:*:*
cpe:2.3:o:mercurycom:mac1200r_firmware:-:*:*:*:*:*:*:*
Vendors & Products Apple
Apple ios And Ipados
Apple visionos
Mercurycom
Mercurycom mac1200r Firmware
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 16 Sep 2024 23:30:00 +0000

Type Values Removed Values Added
Description This issue was addressed by removing the vulnerable code. This issue is fixed in macOS Ventura 13.7, visionOS 2, iOS 18 and iPadOS 18, macOS Sonoma 14.7, macOS Sequoia 15. An app may be able to overwrite arbitrary files.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published: 2024-09-16T23:22:25.822Z

Updated: 2024-09-17T20:44:32.357Z

Reserved: 2024-08-20T21:42:05.925Z

Link: CVE-2024-44167

cve-icon Vulnrichment

Updated: 2024-09-17T20:42:15.777Z

cve-icon NVD

Status : Received

Published: 2024-09-17T00:15:51.310

Modified: 2024-09-18T08:35:53.200

Link: CVE-2024-44167

cve-icon Redhat

No data.