CVE-2024-27833

An integer overflow was addressed with improved input validation. This issue is fixed in tvOS 17.5, iOS 16.7.8 and iPadOS 16.7.8, visionOS 1.2, Safari 17.5, iOS 17.5 and iPadOS 17.5. Processing maliciously crafted web content may lead to arbitrary code execution.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:apple:safari:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:tvos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:visionos:*:*:*:*:*:*:*:*

History

27 Jun 2024, 16:58

Type Values Removed Values Added
CWE CWE-190
First Time Apple tvos
Apple iphone Os
Apple visionos
Apple
Apple safari
Apple ipados
CPE cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*
cpe:2.3:a:apple:safari:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:tvos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:visionos:*:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 8.8
References () http://seclists.org/fulldisclosure/2024/Jun/5 - () http://seclists.org/fulldisclosure/2024/Jun/5 - Mailing List, Third Party Advisory
References () https://support.apple.com/en-us/HT214100 - () https://support.apple.com/en-us/HT214100 - Vendor Advisory
References () https://support.apple.com/en-us/HT214101 - () https://support.apple.com/en-us/HT214101 - Vendor Advisory
References () https://support.apple.com/en-us/HT214102 - () https://support.apple.com/en-us/HT214102 - Vendor Advisory
References () https://support.apple.com/en-us/HT214103 - () https://support.apple.com/en-us/HT214103 - Vendor Advisory
References () https://support.apple.com/en-us/HT214108 - () https://support.apple.com/en-us/HT214108 - Vendor Advisory

12 Jun 2024, 04:15

Type Values Removed Values Added
References
  • () http://seclists.org/fulldisclosure/2024/Jun/5 -

11 Jun 2024, 13:54

Type Values Removed Values Added
Summary
  • (es) Se solucionó un desbordamiento de enteros con una validación de entrada mejorada. Este problema se solucionó en tvOS 17.5, iOS 16.7.8 y iPadOS 16.7.8, visionOS 1.2, Safari 17.5, iOS 17.5 y iPadOS 17.5. El procesamiento de contenido web creado con fines malintencionados puede provocar la ejecución de código arbitrario.

10 Jun 2024, 21:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-06-10 21:15

Updated : 2024-07-03 01:51


NVD link : CVE-2024-27833

Mitre link : CVE-2024-27833

CVE.ORG link : CVE-2024-27833


JSON object : View

Products Affected

apple

  • visionos
  • iphone_os
  • ipados
  • safari
  • tvos
CWE
CWE-190

Integer Overflow or Wraparound