{"id":58533,"date":"2024-07-30T17:40:33","date_gmt":"2024-07-30T14:40:33","guid":{"rendered":"https:\/\/packetstormsecurity.com\/files\/179824\/APPLE-SA-07-29-2024-7.txt"},"modified":"2024-07-30T17:40:33","modified_gmt":"2024-07-30T14:40:33","slug":"apple-security-advisory-07-29-2024-7","status":"publish","type":"post","link":"https:\/\/afaghhosting.net\/blog\/apple-security-advisory-07-29-2024-7\/","title":{"rendered":"Apple Security Advisory 07-29-2024-7"},"content":{"rendered":"<p>&#8212;&#8211;BEGIN PGP SIGNED MESSAGE&#8212;&#8211;<br \/>Hash: SHA256<\/p>\n<p>APPLE-SA-07-29-2024-7 watchOS 10.6<\/p>\n<p>watchOS 10.6 addresses the following issues.<br \/>Information about the security content is also available at<br \/>https:\/\/support.apple.com\/HT214124.<\/p>\n<p>Apple maintains a Security Releases page at<br \/>https:\/\/support.apple.com\/HT201222 which lists recent<br \/>software updates with security advisories.<\/p>\n<p>AppleMobileFileIntegrity<br \/>Available for: Apple Watch Series 4 and later<br \/>Impact: An app may be able to bypass Privacy preferences<br \/>Description: A downgrade issue was addressed with additional code-<br \/>signing restrictions.<br \/>CVE-2024-40774: Mickey Jin (@patch1t)<\/p>\n<p>CoreGraphics<br \/>Available for: Apple Watch Series 4 and later<br \/>Impact: Processing a maliciously crafted file may lead to unexpected app<br \/>termination<br \/>Description: An out-of-bounds read issue was addressed with improved<br \/>input validation.<br \/>CVE-2024-40799: D4m0n<\/p>\n<p>dyld<br \/>Available for: Apple Watch Series 4 and later<br \/>Impact: A malicious attacker with arbitrary read and write capability<br \/>may be able to bypass Pointer Authentication<br \/>Description: A race condition was addressed with additional validation.<br \/>CVE-2024-40815: w0wbox<\/p>\n<p>Family Sharing<br \/>Available for: Apple Watch Series 4 and later<br \/>Impact: An app may be able to read sensitive location information<br \/>Description: This issue was addressed with improved data protection.<br \/>CVE-2024-40795: Csaba Fitzl (@theevilbit) of Kandji<\/p>\n<p>ImageIO<br \/>Available for: Apple Watch Series 4 and later<br \/>Impact: Processing an image may lead to a denial-of-service<br \/>Description: This is a vulnerability in open source code and Apple<br \/>Software is among the affected projects. The CVE-ID was assigned by a<br \/>third party. Learn more about the issue and CVE-ID at cve.org.<br \/>CVE-2023-6277<br \/>CVE-2023-52356<\/p>\n<p>ImageIO<br \/>Available for: Apple Watch Series 4 and later<br \/>Impact: Processing a maliciously crafted file may lead to unexpected app<br \/>termination<br \/>Description: An out-of-bounds read issue was addressed with improved<br \/>input validation.<br \/>CVE-2024-40806: Yisumi<\/p>\n<p>ImageIO<br \/>Available for: Apple Watch Series 4 and later<br \/>Impact: Processing a maliciously crafted file may lead to unexpected app<br \/>termination<br \/>Description: An out-of-bounds access issue was addressed with improved<br \/>bounds checking.<br \/>CVE-2024-40777: Junsung Lee working with Trend Micro Zero Day<br \/>Initiative, Amir Bazine and Karsten K\u00f6nig of CrowdStrike Counter<br \/>Adversary Operations<\/p>\n<p>ImageIO<br \/>Available for: Apple Watch Series 4 and later<br \/>Impact: Processing a maliciously crafted file may lead to unexpected app<br \/>termination<br \/>Description: An integer overflow was addressed with improved input<br \/>validation.<br \/>CVE-2024-40784: Junsung Lee working with Trend Micro Zero Day Initiative<br \/>and Gandalf4a<\/p>\n<p>Kernel<br \/>Available for: Apple Watch Series 4 and later<br \/>Impact: A local attacker may be able to determine kernel memory layout<br \/>Description: An information disclosure issue was addressed with improved<br \/>private data redaction for log entries.<br \/>CVE-2024-27863: CertiK SkyFall Team<\/p>\n<p>Kernel<br \/>Available for: Apple Watch Series 4 and later<br \/>Impact: A local attacker may be able to cause unexpected system shutdown<br \/>Description: A type confusion issue was addressed with improved memory<br \/>handling.<br \/>CVE-2024-40788: Minghao Lin and Jiaxun Zhu from Zhejiang University<\/p>\n<p>libxpc<br \/>Available for: Apple Watch Series 4 and later<br \/>Impact: An app may be able to bypass Privacy preferences<br \/>Description: A permissions issue was addressed with additional<br \/>restrictions.<br \/>CVE-2024-40805<\/p>\n<p>Phone<br \/>Available for: Apple Watch Series 4 and later<br \/>Impact: An attacker with physical access may be able to use Siri to<br \/>access sensitive user data<br \/>Description: A lock screen issue was addressed with improved state<br \/>management.<br \/>CVE-2024-40813: Jacob Braun<\/p>\n<p>Sandbox<br \/>Available for: Apple Watch Series 4 and later<br \/>Impact: An app may be able to bypass Privacy preferences<br \/>Description: This issue was addressed through improved state management.<br \/>CVE-2024-40824: Wojciech Regula of SecuRing (wojciechregula.blog) and<br \/>Zhongquan Li (@Guluisacat) from Dawn Security Lab of JingDong<\/p>\n<p>Shortcuts<br \/>Available for: Apple Watch Series 4 and later<br \/>Impact: A shortcut may be able to use sensitive data with certain<br \/>actions without prompting the user<br \/>Description: A logic issue was addressed with improved checks.<br \/>CVE-2024-40835: an anonymous researcher<br \/>CVE-2024-40836: an anonymous researcher<\/p>\n<p>Shortcuts<br \/>Available for: Apple Watch Series 4 and later<br \/>Impact: A shortcut may be able to bypass Internet permission<br \/>requirements<br \/>Description: A logic issue was addressed with improved checks.<br \/>CVE-2024-40809: an anonymous researcher<br \/>CVE-2024-40812: an anonymous researcher<\/p>\n<p>Shortcuts<br \/>Available for: Apple Watch Series 4 and later<br \/>Impact: A shortcut may be able to bypass Internet permission<br \/>requirements<br \/>Description: This issue was addressed by adding an additional prompt for<br \/>user consent.<br \/>CVE-2024-40787: an anonymous researcher<\/p>\n<p>Shortcuts<br \/>Available for: Apple Watch Series 4 and later<br \/>Impact: An app may be able to access user-sensitive data<br \/>Description: This issue was addressed by removing the vulnerable code.<br \/>CVE-2024-40793: Kirin (@Pwnrin)<\/p>\n<p>Siri<br \/>Available for: Apple Watch Series 4 and later<br \/>Impact: An attacker with physical access may be able to use Siri to<br \/>access sensitive user data<br \/>Description: This issue was addressed by restricting options offered on<br \/>a locked device.<br \/>CVE-2024-40818: Bistrit Dahal and Srijan Poudel<\/p>\n<p>Siri<br \/>Available for: Apple Watch Series 4 and later<br \/>Impact: An attacker with physical access to a device may be able to<br \/>access contacts from the lock screen<br \/>Description: This issue was addressed by restricting options offered on<br \/>a locked device.<br \/>CVE-2024-40822: Srijan Poudel<\/p>\n<p>VoiceOver<br \/>Available for: Apple Watch Series 4 and later<br \/>Impact: An attacker may be able to view restricted content from the lock<br \/>screen<br \/>Description: The issue was addressed with improved checks.<br \/>CVE-2024-40829: Abhay Kailasia (@abhay_kailasia) of Lakshmi Narain<br \/>College of Technology Bhopal India<\/p>\n<p>WebKit<br \/>Available for: Apple Watch Series 4 and later<br \/>Impact: Processing maliciously crafted web content may lead to an<br \/>unexpected process crash<br \/>Description: A use-after-free issue was addressed with improved memory<br \/>management.<br \/>WebKit Bugzilla: 273176<br \/>CVE-2024-40776: Huang Xilin of Ant Group Light-Year Security Lab<br \/>WebKit Bugzilla: 268770<br \/>CVE-2024-40782: Maksymilian Motyl<\/p>\n<p>WebKit<br \/>Available for: Apple Watch Series 4 and later<br \/>Impact: Processing maliciously crafted web content may lead to an<br \/>unexpected process crash<br \/>Description: An out-of-bounds read was addressed with improved bounds<br \/>checking.<br \/>WebKit Bugzilla: 275431<br \/>CVE-2024-40779: Huang Xilin of Ant Group Light-Year Security Lab<br \/>WebKit Bugzilla: 275273<br \/>CVE-2024-40780: Huang Xilin of Ant Group Light-Year Security Lab<\/p>\n<p>WebKit<br \/>Available for: Apple Watch Series 4 and later<br \/>Impact: Processing maliciously crafted web content may lead to a cross<br \/>site scripting attack<br \/>Description: This issue was addressed with improved checks.<br \/>WebKit Bugzilla: 273805<br \/>CVE-2024-40785: Johan Carlsson (joaxcar)<\/p>\n<p>WebKit<br \/>Available for: Apple Watch Series 4 and later<br \/>Impact: Processing maliciously crafted web content may lead to an<br \/>unexpected process crash<br \/>Description: An out-of-bounds access issue was addressed with improved<br \/>bounds checking.<br \/>CVE-2024-40789: Seunghyun Lee (@0x10n) of KAIST Hacking Lab working with<br \/>Trend Micro Zero Day Initiative<\/p>\n<p>Additional recognition<\/p>\n<p>Shortcuts<br \/>We would like to acknowledge an anonymous researcher for their<br \/>assistance.<\/p>\n<p>Instructions on how to update your Apple Watch software are available<br \/>at https:\/\/support.apple.com\/HT204641 To check the version on<br \/>your Apple Watch, open the Apple Watch app on your iPhone and select<br \/>&#8220;My Watch &gt; General &gt; About&#8221;. Alternatively, on your watch, select<br \/>&#8220;My Watch &gt; General &gt; About&#8221;.<br \/>All information is also posted on the Apple Security Releases<br \/>web site: https:\/\/support.apple.com\/HT201222.<\/p>\n<p>This message is signed with Apple&#8217;s Product Security PGP key,<br \/>and details are available at:<br \/>https:\/\/www.apple.com\/support\/security\/pgp\/<br \/>&#8212;&#8211;BEGIN PGP SIGNATURE&#8212;&#8211;<\/p>\n<p>iQIzBAEBCAAdFiEEsz9altA7uTI+rE\/qX+5d1TXaIvoFAmaoICUACgkQX+5d1TXa<br \/>IvoXBQ\/+K5v4MYwo1Lr0ZOzH2g2WI2cuYrXSeos2rbmgHLyriF6TlW8FnwHMBF4c<br \/>1yqOp5vmv7hfkYUHXdIlLX7VUCdYSSu+FAPVjykogqTTa09dsMRMK1mu8MulXxPO<br \/>eSvWdEF8HrPe7Aw45jHIxxilJC50TRDZbIl1HWO4w0qi6G2dNwnQwCLC2BkiqXp7<br \/>7t60Ou9HdILroG3xUUl+EUM+RN7rcqfJ6pkPWmgNUdT31mln7jb++RXzsS00d6ee<br \/>HEH96qVAlEq8A5LQmNmpru8MatI0l5sr1qtfb\/prY0A10lCUb8IwCeDL1v13RAlN<br \/>\/7WWD5sLqM4yhvQKgN956Bmn9ggfzB+BsOORl6Eei6w\/QRi\/caZEC9yty9ylHJqJ<br \/>65ApHnhgEtCul\/uvlzCnVJbZJZBMZYTaVeRftDAp49FH8sBlLyPka4ym\/aeOnU76<br \/>tP7GcDVkmK7oDeCqNuSM0XPxBI7zc2CZ5aZq0y+OBfLWWo0kBORkksyDWylhk0cD<br \/>wAzyyFt0oUgYH7bwpu4pRE5b3ZcaUzt6hCruRCKC+m28sMQ9bkqfuzCResZ+CCHS<br \/>Lf0wg1wI+4AjAcIEEZ13A7v8tKoC0PHr1ByJe7LXSTTdxkiOOHmkhD+Iy6\/Xyc+4<br \/>zRBKwUtbmniB+aHFqU3Qp0eDTFlNAg01lN15BH6pLKwfXD0ERIk=<br \/>=MEx2<br \/>&#8212;&#8211;END PGP SIGNATURE&#8212;&#8211;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>&#8212;&#8211;BEGIN PGP SIGNED MESSAGE&#8212;&#8211;Hash: SHA256 APPLE-SA-07-29-2024-7 watchOS 10.6 watchOS 10.6 addresses the following issues.Information about the security content is also available athttps:\/\/support.apple.com\/HT214124. Apple maintains a Security Releases page athttps:\/\/support.apple.com\/HT201222 which lists recentsoftware updates with security advisories. AppleMobileFileIntegrityAvailable for: Apple Watch Series 4 and laterImpact: An app may be able to bypass Privacy preferencesDescription: A downgrade &hellip;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[26],"tags":[],"class_list":["post-58533","post","type-post","status-publish","format-standard","hentry","category-vulnerability"],"_links":{"self":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts\/58533","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/comments?post=58533"}],"version-history":[{"count":0,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts\/58533\/revisions"}],"wp:attachment":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/media?parent=58533"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/categories?post=58533"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/tags?post=58533"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}