{"id":56856,"date":"2024-05-15T19:39:56","date_gmt":"2024-05-15T15:39:56","guid":{"rendered":"https:\/\/packetstormsecurity.com\/files\/178574\/APPLE-SA-05-13-2024-2.txt"},"modified":"2024-05-15T19:39:56","modified_gmt":"2024-05-15T15:39:56","slug":"apple-security-advisory-05-13-2024-2","status":"publish","type":"post","link":"https:\/\/afaghhosting.net\/blog\/apple-security-advisory-05-13-2024-2\/","title":{"rendered":"Apple Security Advisory 05-13-2024-2"},"content":{"rendered":"<p>&#8212;&#8211;BEGIN PGP SIGNED MESSAGE&#8212;&#8211;<br \/>Hash: SHA256<\/p>\n<p>APPLE-SA-05-13-2024-2 iOS 17.5 and iPadOS 17.5<\/p>\n<p>iOS 17.5 and iPadOS 17.5 addresses the following issues.<br \/>Information about the security content is also available at<br \/>https:\/\/support.apple.com\/HT214101.<\/p>\n<p>Apple maintains a Security Releases page at<br \/>https:\/\/support.apple.com\/HT201222 which lists recent<br \/>software updates with security advisories.<\/p>\n<p>AppleAVD<br \/>Available for: iPhone XS and later, iPad Pro 12.9-inch 2nd generation<br \/>and later, iPad Pro 10.5-inch, iPad Pro 11-inch 1st generation and<br \/>later, iPad Air 3rd generation and later, iPad 6th generation and later,<br \/>and iPad mini 5th generation and later<br \/>Impact: An app may be able to execute arbitrary code with kernel<br \/>privileges<br \/>Description: The issue was addressed with improved memory handling.<br \/>CVE-2024-27804: Meysam Firouzi (@R00tkitSMM)<\/p>\n<p>AppleMobileFileIntegrity<br \/>Available for: iPhone XS and later, iPad Pro 12.9-inch 2nd generation<br \/>and later, iPad Pro 10.5-inch, iPad Pro 11-inch 1st generation and<br \/>later, iPad Air 3rd generation and later, iPad 6th generation and later,<br \/>and iPad mini 5th generation and later<br \/>Impact: An attacker may be able to access user data<br \/>Description: A logic issue was addressed with improved checks.<br \/>CVE-2024-27816: Mickey Jin (@patch1t)<\/p>\n<p>AVEVideoEncoder<br \/>Available for: iPhone XS and later, iPad Pro 12.9-inch 2nd generation<br \/>and later, iPad Pro 10.5-inch, iPad Pro 11-inch 1st generation and<br \/>later, iPad Air 3rd generation and later, iPad 6th generation and later,<br \/>and iPad mini 5th generation and later<br \/>Impact: An app may be able to disclose kernel memory<br \/>Description: The issue was addressed with improved memory handling.<br \/>CVE-2024-27841: an anonymous researcher<\/p>\n<p>Find My<br \/>Available for: iPhone XS and later, iPad Pro 12.9-inch 2nd generation<br \/>and later, iPad Pro 10.5-inch, iPad Pro 11-inch 1st generation and<br \/>later, iPad Air 3rd generation and later, iPad 6th generation and later,<br \/>and iPad mini 5th generation and later<br \/>Impact: A malicious application may be able to determine a user&#8217;s<br \/>current location<br \/>Description: A privacy issue was addressed by moving sensitive data to a<br \/>more secure location.<br \/>CVE-2024-27839: Alexander Heinrich, SEEMOO, TU Darmstadt (@Sn0wfreeze),<br \/>and Shai Mishali (@freak4pc)<\/p>\n<p>Kernel<br \/>Available for: iPhone XS and later, iPad Pro 12.9-inch 2nd generation<br \/>and later, iPad Pro 10.5-inch, iPad Pro 11-inch 1st generation and<br \/>later, iPad Air 3rd generation and later, iPad 6th generation and later,<br \/>and iPad mini 5th generation and later<br \/>Impact: An attacker may be able to cause unexpected app termination or<br \/>arbitrary code execution<br \/>Description: The issue was addressed with improved memory handling.<br \/>CVE-2024-27818: pattern-f (@pattern_F_) of Ant Security Light-Year Lab<\/p>\n<p>Libsystem<br \/>Available for: iPhone XS and later, iPad Pro 12.9-inch 2nd generation<br \/>and later, iPad Pro 10.5-inch, iPad Pro 11-inch 1st generation and<br \/>later, iPad Air 3rd generation and later, iPad 6th generation and later,<br \/>and iPad mini 5th generation and later<br \/>Impact: An app may be able to access protected user data<br \/>Description: A permissions issue was addressed by removing vulnerable<br \/>code and adding additional checks.<br \/>CVE-2023-42893: an anonymous researcher<\/p>\n<p>Maps<br \/>Available for: iPhone XS and later, iPad Pro 12.9-inch 2nd generation<br \/>and later, iPad Pro 10.5-inch, iPad Pro 11-inch 1st generation and<br \/>later, iPad Air 3rd generation and later, iPad 6th generation and later,<br \/>and iPad mini 5th generation and later<br \/>Impact: An app may be able to read sensitive location information<br \/>Description: A path handling issue was addressed with improved<br \/>validation.<br \/>CVE-2024-27810: LFY@secsys of Fudan University<\/p>\n<p>MarketplaceKit<br \/>Available for: iPhone XS and later<br \/>Impact: A maliciously crafted webpage may be able to distribute a script<br \/>that tracks users on other webpages<br \/>Description: A privacy issue was addressed with improved client ID<br \/>handling for alternative app marketplaces.<br \/>CVE-2024-27852: Talal Haj Bakry and Tommy Mysk of Mysk Inc. (@mysk_co)<\/p>\n<p>Notes<br \/>Available for: iPhone XS and later, iPad Pro 12.9-inch 2nd generation<br \/>and later, iPad Pro 10.5-inch, iPad Pro 11-inch 1st generation and<br \/>later, iPad Air 3rd generation and later, iPad 6th generation and later,<br \/>and iPad mini 5th generation and later<br \/>Impact: An attacker with physical access to an iOS device may be able to<br \/>access notes from the lock screen<br \/>Description: This issue was addressed through improved state management.<br \/>CVE-2024-27835: Andr.Ess<\/p>\n<p>RemoteViewServices<br \/>Available for: iPhone XS and later, iPad Pro 12.9-inch 2nd generation<br \/>and later, iPad Pro 10.5-inch, iPad Pro 11-inch 1st generation and<br \/>later, iPad Air 3rd generation and later, iPad 6th generation and later,<br \/>and iPad mini 5th generation and later<br \/>Impact: An attacker may be able to access user data<br \/>Description: A logic issue was addressed with improved checks.<br \/>CVE-2024-27816: Mickey Jin (@patch1t)<\/p>\n<p>Screenshots<br \/>Available for: iPhone XS and later, iPad Pro 12.9-inch 2nd generation<br \/>and later, iPad Pro 10.5-inch, iPad Pro 11-inch 1st generation and<br \/>later, iPad Air 3rd generation and later, iPad 6th generation and later,<br \/>and iPad mini 5th generation and later<br \/>Impact: An attacker with physical access may be able to share items from<br \/>the lock screen<br \/>Description: A permissions issue was addressed with improved validation.<br \/>CVE-2024-27803: an anonymous researcher<\/p>\n<p>Shortcuts<br \/>Available for: iPhone XS and later, iPad Pro 12.9-inch 2nd generation<br \/>and later, iPad Pro 10.5-inch, iPad Pro 11-inch 1st generation and<br \/>later, iPad Air 3rd generation and later, iPad 6th generation and later,<br \/>and iPad mini 5th generation and later<br \/>Impact: A shortcut may output sensitive user data without consent<br \/>Description: A path handling issue was addressed with improved<br \/>validation.<br \/>CVE-2024-27821: Kirin (@Pwnrin), zbleet, and Csaba Fitzl (@theevilbit)<br \/>of Kandji<\/p>\n<p>Sync Services<br \/>Available for: iPhone XS and later, iPad Pro 12.9-inch 2nd generation<br \/>and later, iPad Pro 10.5-inch, iPad Pro 11-inch 1st generation and<br \/>later, iPad Air 3rd generation and later, iPad 6th generation and later,<br \/>and iPad mini 5th generation and later<br \/>Impact: An app may be able to bypass Privacy preferences<br \/>Description: This issue was addressed with improved checks<br \/>CVE-2024-27847: Mickey Jin (@patch1t)<\/p>\n<p>Voice Control<br \/>Available for: iPhone XS and later, iPad Pro 12.9-inch 2nd generation<br \/>and later, iPad Pro 10.5-inch, iPad Pro 11-inch 1st generation and<br \/>later, iPad Air 3rd generation and later, iPad 6th generation and later,<br \/>and iPad mini 5th generation and later<br \/>Impact: An attacker may be able to elevate privileges<br \/>Description: The issue was addressed with improved checks.<br \/>CVE-2024-27796: ajajfxhj<\/p>\n<p>WebKit<br \/>Available for: iPhone XS and later, iPad Pro 12.9-inch 2nd generation<br \/>and later, iPad Pro 10.5-inch, iPad Pro 11-inch 1st generation and<br \/>later, iPad Air 3rd generation and later, iPad 6th generation and later,<br \/>and iPad mini 5th generation and later<br \/>Impact: An attacker with arbitrary read and write capability may be able<br \/>to bypass Pointer Authentication<br \/>Description: The issue was addressed with improved checks.<br \/>WebKit Bugzilla: 272750<br \/>CVE-2024-27834: Manfred Paul (@_manfp) working with Trend Micro&#8217;s Zero<br \/>Day Initiative<\/p>\n<p>Additional recognition<\/p>\n<p>App Store<br \/>We would like to acknowledge an anonymous researcher for their<br \/>assistance.<\/p>\n<p>CoreHAP<br \/>We would like to acknowledge Adrian Cable for their assistance.<\/p>\n<p>Face ID<br \/>We would like to acknowledge Lucas Monteiro, Daniel Monteiro, and Felipe<br \/>Monteiro for their assistance.<\/p>\n<p>HearingCore<br \/>We would like to acknowledge an anonymous researcher for their<br \/>assistance.<\/p>\n<p>Managed Configuration<br \/>We would like to acknowledge \u9065\u9065\u9886\u5148 (@\u6674\u5929\u7ec4\u7ec7) for their assistance.<\/p>\n<p>Safari Downloads<br \/>We would like to acknowledge Arsenii Kostromin (0x3c3e) for their<br \/>assistance.<\/p>\n<p>Status Bar<br \/>We would like to acknowledge Abhay Kailasia (@abhay_kailasia) of Lakshmi<br \/>Narain College of Technology Bhopal for their assistance.<\/p>\n<p>This update is available through iTunes and Software Update on your<br \/>iOS device, and will not appear in your computer&#8217;s Software Update<br \/>application, or in the Apple Downloads site. Make sure you have an<br \/>Internet connection and have installed the latest version of iTunes<br \/>from https:\/\/www.apple.com\/itunes\/ iTunes and Software Update on the<br \/>device will automatically check Apple&#8217;s update server on its weekly<br \/>schedule. When an update is detected, it is downloaded and the option<br \/>to be installed is presented to the user when the iOS device is<br \/>docked. We recommend applying the update immediately if possible.<br \/>Selecting Don&#8217;t Install will present the option the next time you<br \/>connect your iOS device. The automatic update process may take up to<br \/>a week depending on the day that iTunes or the device checks for<br \/>updates. You may manually obtain the update via the Check for Updates<br \/>button within iTunes, or the Software Update on your device. To<br \/>check that the iPhone, iPod touch, or iPad has been updated: *<br \/>Navigate to Settings * Select General * Select About. The version<br \/>after applying this update will be &#8220;iOS 17.5 and iPadOS 17.5&#8221;.<br \/>All information is also posted on the Apple Security Releases<br \/>web site: https:\/\/support.apple.com\/HT201222.<\/p>\n<p>This message is signed with Apple&#8217;s Product Security PGP key,<br \/>and details are available at:<br \/>https:\/\/www.apple.com\/support\/security\/pgp\/<br \/>&#8212;&#8211;BEGIN PGP SIGNATURE&#8212;&#8211;<\/p>\n<p>iQIzBAEBCAAdFiEEsz9altA7uTI+rE\/qX+5d1TXaIvoFAmZCru4ACgkQX+5d1TXa<br \/>IvrSLxAAnqj3N4PyUOrHm+zOFx2kEM5qVOwxJVlqbH9Q6DMG2L54N2iTmyR4X0W8<br \/>5uOA9hmHW9TdR+OT85zMXSXdNWn16BMzUtYQjXTk4pU4dEpcD\/V5Vjs8dq+LX6YH<br \/>1Y9\/M8K\/wh7oAmPfnRQbCitEvwMRpXglHQbfeydUKhri67LeNRYKpYu7KRZrFP+X<br \/>SfFfqJOI4a1FM\/xDgFALCsDVws\/qdk1K9o0NoxEjKcwvTplCoNtHajjW1l3QT4nM<br \/>xgcueMqfJL99nbCzisEmwovbhD17UQDA4zrxrRejCjY233g7uDB6vIkQDCUzSqo8<br \/>2lb+HO0uCMG3rkMQs1jt6iCNYpop4n+tvpLz9DLB+H5PqXXZYQe9dHsEgnuhsMCR<br \/>lpJ7MGgAxEaIs\/bZQLVJKa3UEZXbd4s5OUz3kE8tRx5faFj4zIj+8++W+2vI8q8q<br \/>ZNm2hA\/APket6twiTDOxjO4uFdo\/TGQUtVI+RSAToKAA3k31wNhKXUTTssUb8at9<br \/>Sto+BA3p\/fJ0fZhGWunJ3kABacSuZcp9lQsCB2mIs6f1fBidCCZD+257uaQfNe9b<br \/>hPaiRJj8JIkbNII07U7Yat+86RVNqZemascU5zZJxsV2vLsOTreptkJ4Wot8ghnh<br \/>rozRvGjqYPgmsXV350+6tL651rbbQAJbf8APIohEjUIXFQkg6DI=<br \/>=3eb1<br \/>&#8212;&#8211;END PGP SIGNATURE&#8212;&#8211;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>&#8212;&#8211;BEGIN PGP SIGNED MESSAGE&#8212;&#8211;Hash: SHA256 APPLE-SA-05-13-2024-2 iOS 17.5 and iPadOS 17.5 iOS 17.5 and iPadOS 17.5 addresses the following issues.Information about the security content is also available athttps:\/\/support.apple.com\/HT214101. Apple maintains a Security Releases page athttps:\/\/support.apple.com\/HT201222 which lists recentsoftware updates with security advisories. AppleAVDAvailable for: iPhone XS and later, iPad Pro 12.9-inch 2nd generationand later, iPad &hellip;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[26],"tags":[],"class_list":["post-56856","post","type-post","status-publish","format-standard","hentry","category-vulnerability"],"_links":{"self":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts\/56856","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/comments?post=56856"}],"version-history":[{"count":0,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts\/56856\/revisions"}],"wp:attachment":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/media?parent=56856"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/categories?post=56856"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/tags?post=56856"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}