Cyber Posture

CVE-2024-54523

Medium

Published: 27 January 2025

Published
27 January 2025
Modified
02 April 2026
KEV Added
Patch
CVSS Score 6.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:N/I:H/A:N
EPSS Score 0.0027 50.4th percentile
Risk Priority 13 60% EPSS · 20% KEV · 20% CVSS

Description

The issue was addressed with improved bounds checks. This issue is fixed in iOS 18.2 and iPadOS 18.2, macOS Sequoia 15.2, tvOS 18.2, watchOS 11.2. An app may be able to corrupt coprocessor memory.

Security Summary

CVE-2024-54523 is a vulnerability addressed through improved bounds checks, classified under CWE-787 (Out-of-bounds Write). It affects Apple operating systems prior to the following versions: iOS 18.2, iPadOS 18.2, macOS Sequoia 15.2, tvOS 18.2, and watchOS 11.2. The flaw allows an app to corrupt coprocessor memory, with a CVSS v3.1 base score of 6.3 (AV:L/AC:L/PR:N/UI:R/S:C/C:N/I:H/A:N).

A local attacker with no privileges required can exploit this vulnerability by tricking a user into interacting with a malicious app, such as through social engineering to install or execute it. Successful exploitation enables high integrity impact by corrupting coprocessor memory, potentially leading to arbitrary code execution or other system disruptions within the changed scope, though it does not directly affect confidentiality or availability.

Apple security advisories, detailed in support documents such as https://support.apple.com/en-us/121837, https://support.apple.com/en-us/121839, https://support.apple.com/en-us/121843, and https://support.apple.com/en-us/121844, confirm the issue was fixed via improved bounds checks in the listed software updates. Mitigation requires applying these patches promptly to vulnerable systems.

Details

CWE(s)
NVD-CWE-noinfoCWE-787

Affected Products

apple
ipados
≤ 18.2
apple
iphone os
≤ 18.2
apple
macos
≤ 15.2
apple
tvos
≤ 18.2
apple
watchos
≤ 11.2

References