{"id":56853,"date":"2024-05-15T18:39:56","date_gmt":"2024-05-15T14:39:56","guid":{"rendered":"https:\/\/packetstormsecurity.com\/files\/178576\/APPLE-SA-05-13-2024-4.txt"},"modified":"2024-05-15T18:39:56","modified_gmt":"2024-05-15T14:39:56","slug":"apple-security-advisory-05-13-2024-4","status":"publish","type":"post","link":"https:\/\/afaghhosting.net\/blog\/apple-security-advisory-05-13-2024-4\/","title":{"rendered":"Apple Security Advisory 05-13-2024-4"},"content":{"rendered":"<p>&#8212;&#8211;BEGIN PGP SIGNED MESSAGE&#8212;&#8211;<br \/>Hash: SHA256<\/p>\n<p>APPLE-SA-05-13-2024-4 macOS Sonoma 14.5<\/p>\n<p>macOS Sonoma 14.5 addresses the following issues.<br \/>Information about the security content is also available at<br \/>https:\/\/support.apple.com\/HT214106.<\/p>\n<p>Apple maintains a Security Releases page at<br \/>https:\/\/support.apple.com\/HT201222 which lists recent<br \/>software updates with security advisories.<\/p>\n<p>AppleAVD<br \/>Available for: macOS Sonoma<br \/>Impact: An app may be able to execute arbitrary code with kernel<br \/>privileges<br \/>Description: The issue was addressed with improved memory handling.<br \/>CVE-2024-27804: Meysam Firouzi (@R00tkitSMM)<\/p>\n<p>AppleMobileFileIntegrity<br \/>Available for: macOS Sonoma<br \/>Impact: A local attacker may gain access to Keychain items<br \/>Description: A downgrade issue was addressed with additional code-<br \/>signing restrictions.<br \/>CVE-2024-27837: Mickey Jin (@patch1t) and ajajfxhj<\/p>\n<p>AppleMobileFileIntegrity<br \/>Available for: macOS Sonoma<br \/>Impact: An attacker may be able to access user data<br \/>Description: A logic issue was addressed with improved checks.<br \/>CVE-2024-27816: Mickey Jin (@patch1t)<\/p>\n<p>AppleMobileFileIntegrity<br \/>Available for: macOS Sonoma<br \/>Impact: An app may be able to bypass certain Privacy preferences<br \/>Description: A downgrade issue affecting Intel-based Mac computers was<br \/>addressed with additional code-signing restrictions.<br \/>CVE-2024-27825: Kirin (@Pwnrin)<\/p>\n<p>AppleVA<br \/>Available for: macOS Sonoma<br \/>Impact: Processing a file may lead to unexpected app termination or<br \/>arbitrary code execution<br \/>Description: The issue was addressed with improved memory handling.<br \/>CVE-2024-27829: Amir Bazine and Karsten K\u00f6nig of CrowdStrike Counter<br \/>Adversary Operations, and Pwn2car working with Trend Micro&#8217;s Zero Day<br \/>Initiative<\/p>\n<p>AVEVideoEncoder<br \/>Available for: macOS Sonoma<br \/>Impact: An app may be able to disclose kernel memory<br \/>Description: The issue was addressed with improved memory handling.<br \/>CVE-2024-27841: an anonymous researcher<\/p>\n<p>CFNetwork<br \/>Available for: macOS Sonoma<br \/>Impact: An app may be able to read arbitrary files<br \/>Description: A correctness issue was addressed with improved checks.<br \/>CVE-2024-23236: Ron Masas of Imperva<\/p>\n<p>Finder<br \/>Available for: macOS Sonoma<br \/>Impact: An app may be able to read arbitrary files<br \/>Description: This issue was addressed through improved state management.<br \/>CVE-2024-27827: an anonymous researcher<\/p>\n<p>Kernel<br \/>Available for: macOS Sonoma<br \/>Impact: An attacker may be able to cause unexpected app termination or<br \/>arbitrary code execution<br \/>Description: The issue was addressed with improved memory handling.<br \/>CVE-2024-27818: pattern-f (@pattern_F_) of Ant Security Light-Year Lab<\/p>\n<p>Libsystem<br \/>Available for: macOS Sonoma<br \/>Impact: An app may be able to access protected user data<br \/>Description: A permissions issue was addressed by removing vulnerable<br \/>code and adding additional checks.<br \/>CVE-2023-42893: an anonymous researcher<\/p>\n<p>Maps<br \/>Available for: macOS Sonoma<br \/>Impact: An app may be able to read sensitive location information<br \/>Description: A path handling issue was addressed with improved<br \/>validation.<br \/>CVE-2024-27810: LFY@secsys of Fudan University<\/p>\n<p>PackageKit<br \/>Available for: macOS Sonoma<br \/>Impact: An app may be able to gain root privileges<br \/>Description: A logic issue was addressed with improved restrictions.<br \/>CVE-2024-27822: Scott Johnson, Mykola Grymalyuk of RIPEDA Consulting,<br \/>Jordy Witteman, and Carlos Polop<\/p>\n<p>PackageKit<br \/>Available for: macOS Sonoma<br \/>Impact: An app may be able to elevate privileges<br \/>Description: This issue was addressed by removing the vulnerable code.<br \/>CVE-2024-27824: Pedro T\u00f4rres (@t0rr3sp3dr0)<\/p>\n<p>PrintCenter<br \/>Available for: macOS Sonoma<br \/>Impact: An app may be able to execute arbitrary code out of its sandbox<br \/>or with certain elevated privileges<br \/>Description: The issue was addressed with improved checks.<br \/>CVE-2024-27813: an anonymous researcher<\/p>\n<p>RemoteViewServices<br \/>Available for: macOS Sonoma<br \/>Impact: An attacker may be able to access user data<br \/>Description: A logic issue was addressed with improved checks.<br \/>CVE-2024-27816: Mickey Jin (@patch1t)<\/p>\n<p>SharedFileList<br \/>Available for: macOS Sonoma<br \/>Impact: An app may be able to elevate privileges<br \/>Description: A logic issue was addressed with improved checks.<br \/>CVE-2024-27843: Mickey Jin (@patch1t)<\/p>\n<p>Shortcuts<br \/>Available for: macOS Sonoma<br \/>Impact: A shortcut may output sensitive user data without consent<br \/>Description: A path handling issue was addressed with improved<br \/>validation.<br \/>CVE-2024-27821: Kirin (@Pwnrin), zbleet, and Csaba Fitzl (@theevilbit)<br \/>of Kandji<\/p>\n<p>StorageKit<br \/>Available for: macOS Sonoma<br \/>Impact: An attacker may be able to elevate privileges<br \/>Description: An authorization issue was addressed with improved state<br \/>management.<br \/>CVE-2024-27798: Yann GASCUEL of Alter Solutions<\/p>\n<p>Sync Services<br \/>Available for: macOS Sonoma<br \/>Impact: An app may be able to bypass Privacy preferences<br \/>Description: This issue was addressed with improved checks<br \/>CVE-2024-27847: Mickey Jin (@patch1t)<\/p>\n<p>udf<br \/>Available for: macOS Sonoma<br \/>Impact: An app may be able to execute arbitrary code with kernel<br \/>privileges<br \/>Description: The issue was addressed with improved checks.<br \/>CVE-2024-27842: CertiK SkyFall Team<\/p>\n<p>Voice Control<br \/>Available for: macOS Sonoma<br \/>Impact: An attacker may be able to elevate privileges<br \/>Description: The issue was addressed with improved checks.<br \/>CVE-2024-27796: ajajfxhj<\/p>\n<p>WebKit<br \/>Available for: macOS Sonoma<br \/>Impact: An attacker with arbitrary read and write capability may be able<br \/>to bypass Pointer Authentication<br \/>Description: The issue was addressed with improved checks.<br \/>WebKit Bugzilla: 272750<br \/>CVE-2024-27834: Manfred Paul (@_manfp) working with Trend Micro&#8217;s Zero<br \/>Day Initiative<\/p>\n<p>Additional recognition<\/p>\n<p>App Store<br \/>We would like to acknowledge an anonymous researcher for their<br \/>assistance.<\/p>\n<p>CoreHAP<br \/>We would like to acknowledge Adrian Cable for their assistance.<\/p>\n<p>HearingCore<br \/>We would like to acknowledge an anonymous researcher for their<br \/>assistance.<\/p>\n<p>Managed Configuration<br \/>We would like to acknowledge \u9065\u9065\u9886\u5148 (@\u6674\u5929\u7ec4\u7ec7) for their assistance.<\/p>\n<p>Music<br \/>We would like to acknowledge an anonymous researcher for their<br \/>assistance.<\/p>\n<p>PackageKit<br \/>We would like to acknowledge Mickey Jin (@patch1t) for their assistance.<\/p>\n<p>Safari Downloads<br \/>We would like to acknowledge Arsenii Kostromin (0x3c3e) for their<br \/>assistance.<\/p>\n<p>macOS Sonoma 14.5 may be obtained from the Mac App Store or Apple&#8217;s<br \/>Software Downloads web site: https:\/\/support.apple.com\/downloads\/<br \/>All information is also posted on the Apple Security Releases<br \/>web site: https:\/\/support.apple.com\/HT201222.<\/p>\n<p>This message is signed with Apple&#8217;s Product Security PGP key,<br \/>and details are available at:<br \/>https:\/\/www.apple.com\/support\/security\/pgp\/<br \/>&#8212;&#8211;BEGIN PGP SIGNATURE&#8212;&#8211;<\/p>\n<p>iQIzBAEBCAAdFiEEsz9altA7uTI+rE\/qX+5d1TXaIvoFAmZCs7MACgkQX+5d1TXa<br \/>IvqKHhAApqwSNiF1fzn2XOuX2AH9sPVTbcdRTlWmD9lOfTnvinbn8J0oNSFoXxDS<br \/>9NqJclCmrl4E\/o9d1mUrV9ys1lAI\/Hm0E3Hq2VmrEzd4umlDeRvGN2qFuqF+JnEc<br \/>svHlZcAmGpN9eMvxwMin+PXqchqXItZeAwbE2UzD+xTxQftoe\/SNSgIlTkncBsMO<br \/>kKS3hlGcNH9fIJhvWY0f7NfX6XKmbxtK6+Glx652v0ayvNmtloBMer+lcy7VcNkL<br \/>Na3bykhiALpwon07xGYmzCn6TsrLhsF4bwsXwdJAmKSJ3s\/I8o2SITJtxmRMxv2I<br \/>DXANRFtC+WaaVqmvOC22XcLuFDvKTH719AcdmxDwBLUQ4P1nQEvObp2OLskayhCp<br \/>oEQPrgSWQerdwNse4Hv3JuQrxJWeKCgHTBbWPvfPL5DCX9u8xy\/5QgJevrv8RX3g<br \/>hOxqYtIdLKzGuJZWapgd0Cv+InrId5j0xcaUvGxA33lkTeYiOgXQIqjtvOJRNYqK<br \/>2cS59vJkn3j+RwuVjVf27q802Jt1ET75eEMFVf0VJUvWWkGfOWpHvXs3qiUJYgqX<br \/>TQcZIpZL1W4jpMjYtjqk9sf6thL2xb5eXv7BDBfiRIQJYUrTlyQKlIH9xbSH4wNA<br \/>XyKKhjtfx9dsPI0wceBVBA5BCGrnlqNBtOr3+8OzcWFCe0qWOKc=<br \/>=NXp8<br \/>&#8212;&#8211;END PGP SIGNATURE&#8212;&#8211;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>&#8212;&#8211;BEGIN PGP SIGNED MESSAGE&#8212;&#8211;Hash: SHA256 APPLE-SA-05-13-2024-4 macOS Sonoma 14.5 macOS Sonoma 14.5 addresses the following issues.Information about the security content is also available athttps:\/\/support.apple.com\/HT214106. Apple maintains a Security Releases page athttps:\/\/support.apple.com\/HT201222 which lists recentsoftware updates with security advisories. AppleAVDAvailable for: macOS SonomaImpact: An app may be able to execute arbitrary code with kernelprivilegesDescription: The issue &hellip;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[26],"tags":[],"class_list":["post-56853","post","type-post","status-publish","format-standard","hentry","category-vulnerability"],"_links":{"self":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts\/56853","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/comments?post=56853"}],"version-history":[{"count":0,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts\/56853\/revisions"}],"wp:attachment":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/media?parent=56853"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/categories?post=56853"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/tags?post=56853"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}