{"id":56849,"date":"2024-05-15T18:39:51","date_gmt":"2024-05-15T14:39:51","guid":{"rendered":"https:\/\/packetstormsecurity.com\/files\/178580\/APPLE-SA-05-13-2024-7.txt"},"modified":"2024-05-15T18:39:51","modified_gmt":"2024-05-15T14:39:51","slug":"apple-security-advisory-05-13-2024-7","status":"publish","type":"post","link":"https:\/\/afaghhosting.net\/blog\/apple-security-advisory-05-13-2024-7\/","title":{"rendered":"Apple Security Advisory 05-13-2024-7"},"content":{"rendered":"<p>&#8212;&#8211;BEGIN PGP SIGNED MESSAGE&#8212;&#8211;<br \/>Hash: SHA256<\/p>\n<p>APPLE-SA-05-13-2024-7 watchOS 10.5<\/p>\n<p>watchOS 10.5 addresses the following issues.<br \/>Information about the security content is also available at<br \/>https:\/\/support.apple.com\/HT214104.<\/p>\n<p>Apple maintains a Security Releases page at<br \/>https:\/\/support.apple.com\/HT201222 which lists recent<br \/>software updates with security advisories.<\/p>\n<p>AppleAVD<br \/>Available for: Apple Watch Series 4 and later<br \/>Impact: An app may be able to execute arbitrary code with kernel<br \/>privileges<br \/>Description: The issue was addressed with improved memory handling.<br \/>CVE-2024-27804: Meysam Firouzi (@R00tkitSMM)<\/p>\n<p>AppleMobileFileIntegrity<br \/>Available for: Apple Watch Series 4 and later<br \/>Impact: An attacker may be able to access user data<br \/>Description: A logic issue was addressed with improved checks.<br \/>CVE-2024-27816: Mickey Jin (@patch1t)<\/p>\n<p>Maps<br \/>Available for: Apple Watch Series 4 and later<br \/>Impact: An app may be able to read sensitive location information<br \/>Description: A path handling issue was addressed with improved<br \/>validation.<br \/>CVE-2024-27810: LFY@secsys of Fudan University<\/p>\n<p>RemoteViewServices<br \/>Available for: Apple Watch Series 4 and later<br \/>Impact: An attacker may be able to access user data<br \/>Description: A logic issue was addressed with improved checks.<br \/>CVE-2024-27816: Mickey Jin (@patch1t)<\/p>\n<p>Shortcuts<br \/>Available for: Apple Watch Series 4 and later<br \/>Impact: A shortcut may output sensitive user data without consent<br \/>Description: A path handling issue was addressed with improved<br \/>validation.<br \/>CVE-2024-27821: Kirin (@Pwnrin), zbleet, and Csaba Fitzl (@theevilbit)<br \/>of Kandji<\/p>\n<p>WebKit<br \/>Available for: Apple Watch Series 4 and later<br \/>Impact: An attacker with arbitrary read and write capability may be able<br \/>to bypass Pointer Authentication<br \/>Description: The issue was addressed with improved checks.<br \/>WebKit Bugzilla: 272750<br \/>CVE-2024-27834: Manfred Paul (@_manfp) working with Trend Micro&#8217;s Zero<br \/>Day Initiative<\/p>\n<p>Additional recognition<\/p>\n<p>App Store<br \/>We would like to acknowledge an anonymous researcher for their<br \/>assistance.<\/p>\n<p>CoreHAP<br \/>We would like to acknowledge Adrian Cable for their assistance.<\/p>\n<p>HearingCore<br \/>We would like to acknowledge an anonymous researcher for their<br \/>assistance.<\/p>\n<p>Managed Configuration<br \/>We would like to acknowledge \u9065\u9065\u9886\u5148 (@\u6674\u5929\u7ec4\u7ec7) for their assistance.<\/p>\n<p>Instructions on how to update your Apple Watch software are available<br \/>at https:\/\/support.apple.com\/HT204641 To check the version on<br \/>your Apple Watch, open the Apple Watch app on your iPhone and select<br \/>&#8220;My Watch &gt; General &gt; About&#8221;. Alternatively, on your watch, select<br \/>&#8220;My Watch &gt; General &gt; About&#8221;.<br \/>All information is also posted on the Apple Security Releases<br \/>web site: https:\/\/support.apple.com\/HT201222.<\/p>\n<p>This message is signed with Apple&#8217;s Product Security PGP key,<br \/>and details are available at:<br \/>https:\/\/www.apple.com\/support\/security\/pgp\/<br \/>&#8212;&#8211;BEGIN PGP SIGNATURE&#8212;&#8211;<\/p>\n<p>iQIzBAEBCAAdFiEEsz9altA7uTI+rE\/qX+5d1TXaIvoFAmZCtuoACgkQX+5d1TXa<br \/>IvoryhAA0MH7dQ2spvGCOs9o90Ha8QfUwkzV6S+x\/kjtb+4dVh+Myyyxcq3HfJP\/<br \/>71NRMcHvxM2nE7d23D9TSDdkKqEckR\/vpgRMR9oPPy+bLnqccu7Rx02dIyOcW0AD<br \/>sOI+puKn2oVSENiQte+Rs5RBBslrzG5G+Ezr2BVyk5jA4q8f2yD3vFlc+4K6u4Xf<br \/>xcM0rgqLTQ1Pe4CiJepLZlm5\/I4ub9jNHgYw37lrBg8ptBBOP722Mt+XeuHcE0tr<br \/>SCvoVCDePnbHPNzofgsSlv0bv6CpfvOYKgRouWzb3wf+a9Cg\/2fPN39nZtVt7V+l<br \/>WqSJjgGB71QgwtRpmr\/nWz3VKzSE9xdnu0H6BOrVAC9qYWn1Qz9S0bfTVhWJDCvk<br \/>XyGhpoHrsKOR\/PDjm8nCx7MzqeWxsG\/yaYHileud3a9tAx1g63kDrwaPjpG4sNg1<br \/>U5pvYLE942yOoImWyFkfcnf9UCGqwdYiNR8uFyfuPoBFhiCM85CjwD3tM2UG0H5Q<br \/>xxU1iYNIHPeDd4q5DEaFqtC3nNraY3JGoAO5im7vNFv4JcoiMb8ObNTLDkNduThd<br \/>q1uB74m37Pfqq\/PT2xtnACHfWpvUpu\/Gc0JcUuS+uMB1nUbvPQpNNJqx7WHwk3Q2<br \/>r8OvMZ1Vw+4APbZ7B5Jnj4pkxSAifC2HQ7FqytCGzRzGqHOrF60=<br \/>=+u2d<br \/>&#8212;&#8211;END PGP SIGNATURE&#8212;&#8211;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>&#8212;&#8211;BEGIN PGP SIGNED MESSAGE&#8212;&#8211;Hash: SHA256 APPLE-SA-05-13-2024-7 watchOS 10.5 watchOS 10.5 addresses the following issues.Information about the security content is also available athttps:\/\/support.apple.com\/HT214104. Apple maintains a Security Releases page athttps:\/\/support.apple.com\/HT201222 which lists recentsoftware updates with security advisories. AppleAVDAvailable for: Apple Watch Series 4 and laterImpact: An app may be able to execute arbitrary code with kernelprivilegesDescription: &hellip;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[26],"tags":[],"class_list":["post-56849","post","type-post","status-publish","format-standard","hentry","category-vulnerability"],"_links":{"self":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts\/56849","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/comments?post=56849"}],"version-history":[{"count":0,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts\/56849\/revisions"}],"wp:attachment":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/media?parent=56849"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/categories?post=56849"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/tags?post=56849"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}