Skip to content

Threat Research Knowledge Base

CVE-2024-54477

Description

CVE-2024-54477 allows an application to access sensitive user data. Apple mitigated the vulnerability through stricter checks in recent updates. Reported by Mickey Jin (@patch1t) and Csaba Fitzl (@theevilbit) of Kandji.

Get a Free Trial

Impact

Grants unauthorized access to sensitive user information. The severity of this issue has been assessed as follows:

NIST assessment

CVSS v3.1 Base Score: 5.5 (Medium)

AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

CISA-ADP assessment

CVSS v3.1 Base Score: 5.5 (Medium)

AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

Has been exploited in the wild

No

Operating systems impacted

  • macOS Ventura (prior to 13.7.2)
  • macOS Sonoma (prior to 14.7.2)
  • macOS Sequoia (prior to 15.2)

Apps impacted

No apps impacted

Related

Exploitation of this vulnerability could lead to unauthorized modification of protected file system areas by an application. The severity of this issue has been assessed as follows:

Exploitation of this vulnerability could lead to unauthorized modification of protected file system areas by an application. The severity of this issue has been assessed as follows:

Exploitation of this vulnerability could allow attackers to execute arbitrary code on the affected devices, leading to potential data breaches, unauthorized access, or further compromise of the system. Apple has acknowledged reports that this issue may have been exploited in extremely sophisticated attacks against specific targeted individuals on versions of iOS before iOS 17.2. The severity of this issue has been assessed as follows:

Manage and secure your Apple devices at scale.

Laptop and 2 popup windows