{"id":56848,"date":"2024-05-15T18:39:50","date_gmt":"2024-05-15T14:39:50","guid":{"rendered":"https:\/\/packetstormsecurity.com\/files\/178581\/APPLE-SA-05-13-2024-8.txt"},"modified":"2024-05-15T18:39:50","modified_gmt":"2024-05-15T14:39:50","slug":"apple-security-advisory-05-13-2024-8","status":"publish","type":"post","link":"https:\/\/afaghhosting.net\/blog\/apple-security-advisory-05-13-2024-8\/","title":{"rendered":"Apple Security Advisory 05-13-2024-8"},"content":{"rendered":"<p>&#8212;&#8211;BEGIN PGP SIGNED MESSAGE&#8212;&#8211;<br \/>Hash: SHA256<\/p>\n<p>APPLE-SA-05-13-2024-8 tvOS 17.5<\/p>\n<p>tvOS 17.5 addresses the following issues.<br \/>Information about the security content is also available at<br \/>https:\/\/support.apple.com\/HT214102.<\/p>\n<p>Apple maintains a Security Releases page at<br \/>https:\/\/support.apple.com\/HT201222 which lists recent<br \/>software updates with security advisories.<\/p>\n<p>AppleAVD<br \/>Available for: Apple TV HD and Apple TV 4K (all models)<br \/>Impact: An app may be able to execute arbitrary code with kernel<br \/>privileges<br \/>Description: The issue was addressed with improved memory handling.<br \/>CVE-2024-27804: Meysam Firouzi (@R00tkitSMM)<\/p>\n<p>AppleMobileFileIntegrity<br \/>Available for: Apple TV HD and Apple TV 4K (all models)<br \/>Impact: An attacker may be able to access user data<br \/>Description: A logic issue was addressed with improved checks.<br \/>CVE-2024-27816: Mickey Jin (@patch1t)<\/p>\n<p>Maps<br \/>Available for: Apple TV HD and Apple TV 4K (all models)<br \/>Impact: An app may be able to read sensitive location information<br \/>Description: A path handling issue was addressed with improved<br \/>validation.<br \/>CVE-2024-27810: LFY@secsys of Fudan University<\/p>\n<p>RemoteViewServices<br \/>Available for: Apple TV HD and Apple TV 4K (all models)<br \/>Impact: An attacker may be able to access user data<br \/>Description: A logic issue was addressed with improved checks.<br \/>CVE-2024-27816: Mickey Jin (@patch1t)<\/p>\n<p>WebKit<br \/>Available for: Apple TV HD and Apple TV 4K (all models)<br \/>Impact: An attacker with arbitrary read and write capability may be able<br \/>to bypass Pointer Authentication<br \/>Description: The issue was addressed with improved checks.<br \/>WebKit Bugzilla: 272750<br \/>CVE-2024-27834: Manfred Paul (@_manfp) working with Trend Micro&#8217;s Zero<br \/>Day Initiative<\/p>\n<p>Additional recognition<\/p>\n<p>App Store<br \/>We would like to acknowledge an anonymous researcher for their<br \/>assistance.<\/p>\n<p>CoreHAP<br \/>We would like to acknowledge Adrian Cable for their assistance.<\/p>\n<p>Managed Configuration<br \/>We would like to acknowledge \u9065\u9065\u9886\u5148 (@\u6674\u5929\u7ec4\u7ec7) for their assistance.<\/p>\n<p>Apple TV will periodically check for software updates. Alternatively,<br \/>you may manually check for software updates by selecting &#8220;Settings -&gt;<br \/>System -&gt; Software Update -&gt; Update Software.&#8221; To check the current<br \/>version of software, select &#8220;Settings -&gt; General -&gt; About.&#8221;<br \/>All information is also posted on the Apple Security Releases<br \/>web site: https:\/\/support.apple.com\/HT201222.<\/p>\n<p>This message is signed with Apple&#8217;s Product Security PGP key,<br \/>and details are available at:<br \/>https:\/\/www.apple.com\/support\/security\/pgp\/<br \/>&#8212;&#8211;BEGIN PGP SIGNATURE&#8212;&#8211;<\/p>\n<p>iQIzBAEBCAAdFiEEsz9altA7uTI+rE\/qX+5d1TXaIvoFAmZCtmQACgkQX+5d1TXa<br \/>IvpH5hAAtZjOJDsDvmKZhDYNv+q147EOgkWQL99zvmBReygAUqk+KoLQQkkfRLP7<br \/>zTw53l3zvcH5Tar065NTIr\/9jW3MDlZ9ipKU5pwy2R6tWRkh5zug6T7WINpcLybv<br \/>6U39illkCn4EOyTZSoET\/kkbuu\/CQ6QUPC\/CX5R\/FtBmAmLNcImRjIgHqRjQKVhO<br \/>9ACminYR+gUbsSqn5OfU0hwbvX2pXzqzE8LoOmhgpJyJIbyUUPHt5C6DYmJ79dlf<br \/>Ui0rXKF+kwzqDrAPxph3XhCW0F+IvceREMLefUQXxvQ\/0eDZhkCGwyw4\/zezoXhg<br \/>k\/rAGQ7EEd27AqyDGyRoLpmFvIXafTp3OrePNPnyjE7j06syH4NnkwQoLerdrW9x<br \/>KOCWQYJ9v03SfJpzGQOVA+aP2sHe4jSR4mtq7m7dax6qKjKrLWog7aqu6+pZZ4Ga<br \/>9AXLEU7sQgNF8TWosVgpUmQEas8v3GQflUqjHvczPyPr4T8Br5VhiM8FYj9SWsPb<br \/>mO\/57\/3kdsaU6DrD1C1mf5SAjFFi65ox78n8hdXOe1B02fvpDOXyz278XBuVMWE0<br \/>CfhrwhXicP0itQp\/KtgrnT+iUhkuPieNBiped\/KHPfe9YXOfpjGrtcPQfximiYsD<br \/>rGPnxm5tCJPobmTzRUdsu9TSInqUP291SOvkyX1DEQUkIszm6ao=<br \/>=oc3g<br \/>&#8212;&#8211;END PGP SIGNATURE&#8212;&#8211;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>&#8212;&#8211;BEGIN PGP SIGNED MESSAGE&#8212;&#8211;Hash: SHA256 APPLE-SA-05-13-2024-8 tvOS 17.5 tvOS 17.5 addresses the following issues.Information about the security content is also available athttps:\/\/support.apple.com\/HT214102. Apple maintains a Security Releases page athttps:\/\/support.apple.com\/HT201222 which lists recentsoftware updates with security advisories. AppleAVDAvailable for: Apple TV HD and Apple TV 4K (all models)Impact: An app may be able to execute arbitrary &hellip;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[26],"tags":[],"class_list":["post-56848","post","type-post","status-publish","format-standard","hentry","category-vulnerability"],"_links":{"self":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts\/56848","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/comments?post=56848"}],"version-history":[{"count":0,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts\/56848\/revisions"}],"wp:attachment":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/media?parent=56848"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/categories?post=56848"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/tags?post=56848"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}