NA

CVE-2024-27834

Published: 14/05/2024 Updated: 14/05/2024

Vulnerability Summary

The issue was addressed with improved checks. This issue is fixed in iOS 17.5 and iPadOS 17.5, tvOS 17.5, Safari 17.5, watchOS 10.5, macOS Sonoma 14.5. An attacker with arbitrary read and write capability may be able to bypass Pointer Authentication.

Vulnerability Trend

Vendor Advisories

About Apple security updates For our customers' protection, Apple doesn't disclose, discuss, or confirm security issues until an investigation has occurred and patches or releases are available Recent releases are listed on the Apple security releases page Apple security documents reference vulnerabilities by CVE-ID whe ...
About Apple security updates For our customers' protection, Apple doesn't disclose, discuss, or confirm security issues until an investigation has occurred and patches or releases are available Recent releases are listed on the Apple security releases page Apple security documents reference vulnerabilities by CVE-ID whe ...
About Apple security updates For our customers' protection, Apple doesn't disclose, discuss, or confirm security issues until an investigation has occurred and patches or releases are available Recent releases are listed on the Apple security releases page Apple security documents reference vulnerabilities by CVE-ID whe ...
About Apple security updates For our customers' protection, Apple doesn't disclose, discuss, or confirm security issues until an investigation has occurred and patches or releases are available Recent releases are listed on the Apple security releases page Apple security documents reference vulnerabilities by CVE-ID whe ...
About Apple security updates For our customers' protection, Apple doesn't disclose, discuss, or confirm security issues until an investigation has occurred and patches or releases are available Recent releases are listed on the Apple security releases page Apple security documents reference vulnerabilities by CVE-ID whe ...

Mailing Lists

-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 APPLE-SA-05-13-2024-7 watchOS 105 watchOS 105 addresses the following issues Information about the security content is also available at supportapplecom/HT214104 Apple maintains a Security Releases page at supportapplecom/HT201222 which lists recent software updates with sec ...
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 APPLE-SA-05-13-2024-4 macOS Sonoma 145 macOS Sonoma 145 addresses the following issues Information about the security content is also available at supportapplecom/HT214106 Apple maintains a Security Releases page at supportapplecom/HT201222 which lists recent software update ...
------------------------------------------------------------------------ WebKitGTK and WPE WebKit Security Advisory WSA-2024-0003 ------------------------------------------------------------------------ Date reported : May 21, 2024 Advisory ID : WSA-2024-0003 WebKitGTK Advisory URL : webkitgtkorg/sec ...

Recent Articles

Apple fixes Safari WebKit zero-day flaw exploited at Pwn2Own
BleepingComputer • Sergiu Gatlan • 14 May 2024

Apple fixes Safari WebKit zero-day flaw exploited at Pwn2Own By Sergiu Gatlan May 14, 2024 11:56 AM 0 Apple has released security updates to fix a zero-day vulnerability in the Safari web browser exploited during this year's Pwn2Own Vancouver hacking competition. The company addressed the security flaw (tracked as CVE-2024-27834) on systems running macOS Monterey and macOS Ventura with improved checks. While Apple only said that the vulnerability was reported by Manfred Paul, working with Trend ...

Microsoft fixes a bug abused in QakBot attacks plus a second under exploit
The Register

Topics Security Off-Prem On-Prem Software Offbeat Special Features Vendor Voice Vendor Voice Resources Plus: Google Chrome, Apple bugs also exploited in the wild

Happy May Patch Tuesday. We've got a lot of vendors joining this month's patchapalooza, which includes a handful of bugs that have been exploited — either in the wild or at Pwn2Own — and now fixed by Microsoft, Apple, Google and VMware. Starting with Microsoft: Redmond disclosed and fixed 60 Windows CVEs today including two listed as publicly known and exploited prior to the patch being issued. The first one is an elevation of privilege bug in Windows DWM core library, tracked as CVE-2024-30...