{"id":58531,"date":"2024-07-30T17:40:31","date_gmt":"2024-07-30T14:40:31","guid":{"rendered":"https:\/\/packetstormsecurity.com\/files\/179826\/APPLE-SA-07-29-2024-9.txt"},"modified":"2024-07-30T17:40:31","modified_gmt":"2024-07-30T14:40:31","slug":"apple-security-advisory-07-29-2024-9","status":"publish","type":"post","link":"https:\/\/afaghhosting.net\/blog\/apple-security-advisory-07-29-2024-9\/","title":{"rendered":"Apple Security Advisory 07-29-2024-9"},"content":{"rendered":"<p>&#8212;&#8211;BEGIN PGP SIGNED MESSAGE&#8212;&#8211;<br \/>Hash: SHA256<\/p>\n<p>APPLE-SA-07-29-2024-9 visionOS 1.3<\/p>\n<p>visionOS 1.3 addresses the following issues.<br \/>Information about the security content is also available at<br \/>https:\/\/support.apple.com\/HT214123.<\/p>\n<p>Apple maintains a Security Releases page at<br \/>https:\/\/support.apple.com\/HT201222 which lists recent<br \/>software updates with security advisories.<\/p>\n<p>Apple Neural Engine<br \/>Available for: Apple Vision Pro<br \/>Impact: A local attacker may be able to cause unexpected system shutdown<br \/>Description: The issue was addressed with improved memory handling.<br \/>CVE-2024-27826: Ye Zhang (@VAR10CK) of Baidu Security and Minghao Lin<\/p>\n<p>AppleAVD<br \/>Available for: Apple Vision Pro<br \/>Impact: An app may be able to cause unexpected system termination<br \/>Description: The issue was addressed with improved memory handling.<br \/>CVE-2024-27804: Meysam Firouzi (@R00tkitSMM)<\/p>\n<p>CoreGraphics<br \/>Available for: Apple Vision Pro<br \/>Impact: Processing a maliciously crafted file may lead to unexpected app<br \/>termination<br \/>Description: An out-of-bounds read issue was addressed with improved<br \/>input validation.<br \/>CVE-2024-40799: D4m0n <\/p>\n<p>ImageIO<br \/>Available for: Apple Vision Pro<br \/>Impact: Processing an image may lead to a denial-of-service<br \/>Description: This is a vulnerability in open source code and Apple<br \/>Software is among the affected projects. The CVE-ID was assigned by a<br \/>third party. Learn more about the issue and CVE-ID at cve.org.<br \/>CVE-2023-6277<br \/>CVE-2023-52356<\/p>\n<p>ImageIO<br \/>Available for: Apple Vision Pro<br \/>Impact: Processing a maliciously crafted file may lead to unexpected app<br \/>termination<br \/>Description: An out-of-bounds read issue was addressed with improved<br \/>input validation.<br \/>CVE-2024-40806: Yisumi<\/p>\n<p>ImageIO<br \/>Available for: Apple Vision Pro<br \/>Impact: Processing a maliciously crafted file may lead to unexpected app<br \/>termination<br \/>Description: An out-of-bounds access issue was addressed with improved<br \/>bounds checking.<br \/>CVE-2024-40777: Junsung Lee working with Trend Micro Zero Day<br \/>Initiative, and Amir Bazine and Karsten K\u00f6nig of CrowdStrike Counter<br \/>Adversary Operations<\/p>\n<p>ImageIO<br \/>Available for: Apple Vision Pro<br \/>Impact: Processing a maliciously crafted file may lead to unexpected app<br \/>termination<br \/>Description: An integer overflow was addressed with improved input<br \/>validation.<br \/>CVE-2024-40784: Junsung Lee working with Trend Micro Zero Day Initiative<br \/>and Gandalf4a<\/p>\n<p>Kernel<br \/>Available for: Apple Vision Pro<br \/>Impact: A local attacker may be able to determine kernel memory layout<br \/>Description: An information disclosure issue was addressed with improved<br \/>private data redaction for log entries.<br \/>CVE-2024-27863: CertiK SkyFall Team<\/p>\n<p>Kernel<br \/>Available for: Apple Vision Pro<br \/>Impact: An attacker in a privileged network position may be able to<br \/>spoof network packets<br \/>Description: A race condition was addressed with improved locking.<br \/>CVE-2024-27823: Prof. Benny Pinkas of Bar-Ilan University, Prof. Amit<br \/>Klein of Hebrew University, and EP<\/p>\n<p>Kernel<br \/>Available for: Apple Vision Pro<br \/>Impact: A local attacker may be able to cause unexpected system shutdown<br \/>Description: A type confusion issue was addressed with improved memory<br \/>handling.<br \/>CVE-2024-40788: Minghao Lin and Jiaxun Zhu from Zhejiang University<\/p>\n<p>Shortcuts<br \/>Available for: Apple Vision Pro<br \/>Impact: A shortcut may be able to bypass Internet permission<br \/>requirements<br \/>Description: A logic issue was addressed with improved checks.<br \/>CVE-2024-40809: an anonymous researcher<br \/>CVE-2024-40812: an anonymous researcher<\/p>\n<p>WebKit<br \/>Available for: Apple Vision Pro<br \/>Impact: Processing maliciously crafted web content may lead to an<br \/>unexpected process crash<br \/>Description: A use-after-free issue was addressed with improved memory<br \/>management.<br \/>WebKit Bugzilla: 273176<br \/>CVE-2024-40776: Huang Xilin of Ant Group Light-Year Security Lab<br \/>WebKit Bugzilla: 268770<br \/>CVE-2024-40782: Maksymilian Motyl<\/p>\n<p>WebKit<br \/>Available for: Apple Vision Pro<br \/>Impact: Processing maliciously crafted web content may lead to an<br \/>unexpected process crash<br \/>Description: An out-of-bounds read was addressed with improved bounds<br \/>checking.<br \/>WebKit Bugzilla: 275431<br \/>CVE-2024-40779: Huang Xilin of Ant Group Light-Year Security Lab<br \/>WebKit Bugzilla: 275273<br \/>CVE-2024-40780: Huang Xilin of Ant Group Light-Year Security Lab<\/p>\n<p>WebKit<br \/>Available for: Apple Vision Pro<br \/>Impact: Processing maliciously crafted web content may lead to a cross<br \/>site scripting attack<br \/>Description: This issue was addressed with improved checks.<br \/>WebKit Bugzilla: 273805<br \/>CVE-2024-40785: Johan Carlsson (joaxcar)<\/p>\n<p>WebKit<br \/>Available for: Apple Vision Pro<br \/>Impact: Processing maliciously crafted web content may lead to an<br \/>unexpected process crash<br \/>Description: An out-of-bounds access issue was addressed with improved<br \/>bounds checking.<br \/>CVE-2024-40789: Seunghyun Lee (@0x10n) of KAIST Hacking Lab working with<br \/>Trend Micro Zero Day Initiative<\/p>\n<p>Additional recognition<\/p>\n<p>AirDrop<br \/>We would like to acknowledge Linwz of DEVCORE for their assistance.<\/p>\n<p>Shortcuts<br \/>We would like to acknowledge an anonymous researcher for their<br \/>assistance.<\/p>\n<p>Instructions on how to update visionOS are available at<br \/>https:\/\/support.apple.com\/HT214009 To check the software version<br \/>on your Apple Vision Pro, open the Settings app and choose General &gt;<br \/>About.<br \/>All information is also posted on the Apple Security Releases<br \/>web site: https:\/\/support.apple.com\/HT201222.<\/p>\n<p>This message is signed with Apple&#8217;s Product Security PGP key,<br \/>and details are available at:<br \/>https:\/\/www.apple.com\/support\/security\/pgp\/<br \/>&#8212;&#8211;BEGIN PGP SIGNATURE&#8212;&#8211;<\/p>\n<p>iQIzBAEBCAAdFiEEsz9altA7uTI+rE\/qX+5d1TXaIvoFAmaoIKEACgkQX+5d1TXa<br \/>IvrPMhAAvJRTT2vBEmsCe8fWRLfDlgrh95ubjnuQ0VJ+dbM2MrdUXZr\/bueevkhJ<br \/>K8bCqDg19hqeWStGG2FoVB0lThZOiS7BIBYyNmfKKyID25dXKUUGVSluLTATOFCs<br \/>YVruEya71fuY4JAFI6c6S2rCfbTDLS0\/8Iq72LQX\/umUo5DD9YX\/fBgKA7ji6KML<br \/>49cOpRpT6xG2OYEFG+GQw4p8\/ha4Dg1QSPhSgYs1n0iwv2Al5siedmhxT+j8Xnof<br \/>O0Wo54q+e7lIMTQaj8SLKh2zysYpHGNREaUIfGKCyr0FuJCEkWdGNaMlNeqI602z<br \/>CYVnLLr3H0tcOGSQtmlUodPQEjunGs3j1AUkZuezagHZzqmR1Tlh4tt3tx3s0B3+<br \/>nxIoA2ejJH6no5gvaOFZmc8MgUgwL0\/LO\/GRm6Ow9lu9N8Bbey34s5h4bnn78\/M+<br \/>W11upSvy6j2C7Nz5n6KgySSmj3sx0AGw199+MoR3iu1+3dGt332CYCIzDI\/9WJTg<br \/>sdVFJD7ZLLSjt2lDD5FkJqoAy1kkTqi9eSsbOVlfYEgBvUr4zvvL8mNgx1\/l6mFH<br \/>9w+rOTo1inMKLwwtPuqJQhEq0uUSY7LcAjIqUBmPWu1PENpeGIOQaSNxkL35SGkB<br \/>6lAKhD6YpkFIrwzuGMtfD9wwPC4OK48BfOV5YMNH4YLT0G4RjMQ=<br \/>=E3LP<br \/>&#8212;&#8211;END PGP SIGNATURE&#8212;&#8211;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>&#8212;&#8211;BEGIN PGP SIGNED MESSAGE&#8212;&#8211;Hash: SHA256 APPLE-SA-07-29-2024-9 visionOS 1.3 visionOS 1.3 addresses the following issues.Information about the security content is also available athttps:\/\/support.apple.com\/HT214123. Apple maintains a Security Releases page athttps:\/\/support.apple.com\/HT201222 which lists recentsoftware updates with security advisories. Apple Neural EngineAvailable for: Apple Vision ProImpact: A local attacker may be able to cause unexpected system shutdownDescription: The &hellip;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[26],"tags":[],"class_list":["post-58531","post","type-post","status-publish","format-standard","hentry","category-vulnerability"],"_links":{"self":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts\/58531","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/comments?post=58531"}],"version-history":[{"count":0,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts\/58531\/revisions"}],"wp:attachment":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/media?parent=58531"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/categories?post=58531"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/tags?post=58531"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}