{"id":59765,"date":"2024-09-17T20:29:42","date_gmt":"2024-09-17T17:29:42","guid":{"rendered":"https:\/\/packetstormsecurity.com\/files\/181576\/APPLE-SA-09-16-2024-8.txt"},"modified":"2024-09-17T20:29:42","modified_gmt":"2024-09-17T17:29:42","slug":"apple-security-advisory-09-16-2024-8","status":"publish","type":"post","link":"https:\/\/afaghhosting.net\/blog\/apple-security-advisory-09-16-2024-8\/","title":{"rendered":"Apple Security Advisory 09-16-2024-8"},"content":{"rendered":"<p>&#8212;&#8211;BEGIN PGP SIGNED MESSAGE&#8212;&#8211;<br \/>Hash: SHA256<\/p>\n<p>APPLE-SA-09-16-2024-8 iOS 17.7 and iPadOS 17.7<\/p>\n<p>iOS 17.7 and iPadOS 17.7 addresses the following issues.<br \/>Information about the security content is also available at<br \/>https:\/\/support.apple.com\/121246.<\/p>\n<p>Apple maintains a Security Releases page at<br \/>https:\/\/support.apple.com\/100100 which lists recent<br \/>software updates with security advisories.<\/p>\n<p>Accessibility<br \/>Available for: iPhone XS and later, iPad Pro 13-inch, iPad Pro 12.9-inch<br \/>2nd generation and later, iPad Pro 10.5-inch, iPad Pro 11-inch 1st<br \/>generation and later, iPad Air 3rd generation and later, iPad 6th<br \/>generation and later, and iPad mini 5th generation and later<br \/>Impact: An attacker with physical access to a locked device may be able<br \/>to Control Nearby Devices via accessibility features<br \/>Description: This issue was addressed through improved state management.<br \/>CVE-2024-44171: Jake Derouin<\/p>\n<p>Compression<br \/>Available for: iPhone XS and later, iPad Pro 13-inch, iPad Pro 12.9-inch<br \/>2nd generation and later, iPad Pro 10.5-inch, iPad Pro 11-inch 1st<br \/>generation and later, iPad Air 3rd generation and later, iPad 6th<br \/>generation and later, and iPad mini 5th generation and later<br \/>Impact: Unpacking a maliciously crafted archive may allow an attacker to<br \/>write arbitrary files<br \/>Description: A race condition was addressed with improved locking.<br \/>CVE-2024-27876: Snoolie Keffaber (@0xilis)<\/p>\n<p>Game Center<br \/>Available for: iPhone XS and later, iPad Pro 13-inch, iPad Pro 12.9-inch<br \/>2nd generation and later, iPad Pro 10.5-inch, iPad Pro 11-inch 1st<br \/>generation and later, iPad Air 3rd generation and later, iPad 6th<br \/>generation and later, and iPad mini 5th generation and later<br \/>Impact: An app may be able to access user-sensitive data<br \/>Description: A file access issue was addressed with improved input<br \/>validation.<br \/>CVE-2024-40850: Denis Tokarev (@illusionofcha0s)<\/p>\n<p>ImageIO<br \/>Available for: iPhone XS and later, iPad Pro 13-inch, iPad Pro 12.9-inch<br \/>2nd generation and later, iPad Pro 10.5-inch, iPad Pro 11-inch 1st<br \/>generation and later, iPad Air 3rd generation and later, iPad 6th<br \/>generation and later, and iPad mini 5th generation and later<br \/>Impact: Processing a maliciously crafted file may lead to unexpected app<br \/>termination<br \/>Description: An out-of-bounds read issue was addressed with improved<br \/>input validation.<br \/>CVE-2024-27880: Junsung Lee<\/p>\n<p>ImageIO<br \/>Available for: iPhone XS and later, iPad Pro 13-inch, iPad Pro 12.9-inch<br \/>2nd generation and later, iPad Pro 10.5-inch, iPad Pro 11-inch 1st<br \/>generation and later, iPad Air 3rd generation and later, iPad 6th<br \/>generation and later, and iPad mini 5th generation and later<br \/>Impact: Processing an image may lead to a denial-of-service<br \/>Description: An out-of-bounds access issue was addressed with improved<br \/>bounds checking.<br \/>CVE-2024-44176: dw0r of ZeroPointer Lab working with Trend Micro Zero<br \/>Day Initiative, an anonymous researcher<\/p>\n<p>IOSurfaceAccelerator<br \/>Available for: iPhone XS and later, iPad Pro 13-inch, iPad Pro 12.9-inch<br \/>2nd generation and later, iPad Pro 10.5-inch, iPad Pro 11-inch 1st<br \/>generation and later, iPad Air 3rd generation and later, iPad 6th<br \/>generation and later, and iPad mini 5th generation and later<br \/>Impact: An app may be able to cause unexpected system termination<br \/>Description: The issue was addressed with improved memory handling.<br \/>CVE-2024-44169: Antonio Zeki\u0107<\/p>\n<p>Kernel<br \/>Available for: iPhone XS and later, iPad Pro 13-inch, iPad Pro 12.9-inch<br \/>2nd generation and later, iPad Pro 10.5-inch, iPad Pro 11-inch 1st<br \/>generation and later, iPad Air 3rd generation and later, iPad 6th<br \/>generation and later, and iPad mini 5th generation and later<br \/>Impact: Network traffic may leak outside a VPN tunnel<br \/>Description: A logic issue was addressed with improved checks.<br \/>CVE-2024-44165: Andrew Lytvynov<\/p>\n<p>Kernel<br \/>Available for: iPhone XS and later, iPad Pro 13-inch, iPad Pro 12.9-inch<br \/>2nd generation and later, iPad Pro 10.5-inch, iPad Pro 11-inch 1st<br \/>generation and later, iPad Air 3rd generation and later, iPad 6th<br \/>generation and later, and iPad mini 5th generation and later<br \/>Impact: An app may gain unauthorized access to Bluetooth<br \/>Description: This issue was addressed through improved state management.<br \/>CVE-2024-44191: Alexander Heinrich, SEEMOO, DistriNet, KU Leuven<br \/>(@vanhoefm), TU Darmstadt (@Sn0wfreeze) and Mathy Vanhoef<\/p>\n<p>Mail Accounts<br \/>Available for: iPhone XS and later, iPad Pro 13-inch, iPad Pro 12.9-inch<br \/>2nd generation and later, iPad Pro 10.5-inch, iPad Pro 11-inch 1st<br \/>generation and later, iPad Air 3rd generation and later, iPad 6th<br \/>generation and later, and iPad mini 5th generation and later<br \/>Impact: An app may be able to access information about a user&#8217;s contacts<br \/>Description: A privacy issue was addressed with improved private data<br \/>redaction for log entries.<br \/>CVE-2024-40791: Rodolphe BRUNETTI (@eisw0lf)<\/p>\n<p>mDNSResponder<br \/>Available for: iPhone XS and later, iPad Pro 13-inch, iPad Pro 12.9-inch<br \/>2nd generation and later, iPad Pro 10.5-inch, iPad Pro 11-inch 1st<br \/>generation and later, iPad Air 3rd generation and later, iPad 6th<br \/>generation and later, and iPad mini 5th generation and later<br \/>Impact: An app may be able to cause a denial-of-service<br \/>Description: A logic error was addressed with improved error handling.<br \/>CVE-2024-44183: Olivier Levon<\/p>\n<p>Safari Private Browsing<br \/>Available for: iPhone XS and later, iPad Pro 13-inch, iPad Pro 12.9-inch<br \/>2nd generation and later, iPad Pro 10.5-inch, iPad Pro 11-inch 1st<br \/>generation and later, iPad Air 3rd generation and later, iPad 6th<br \/>generation and later, and iPad mini 5th generation and later<br \/>Impact: Private Browsing tabs may be accessed without authentication<br \/>Description: This issue was addressed through improved state management.<br \/>CVE-2024-44127: Anamika Adhikari<\/p>\n<p>Shortcuts<br \/>Available for: iPhone XS and later, iPad Pro 13-inch, iPad Pro 12.9-inch<br \/>2nd generation and later, iPad Pro 10.5-inch, iPad Pro 11-inch 1st<br \/>generation and later, iPad Air 3rd generation and later, iPad 6th<br \/>generation and later, and iPad mini 5th generation and later<br \/>Impact: A shortcut may output sensitive user data without consent<br \/>Description: This issue was addressed with improved redaction of<br \/>sensitive information.<br \/>CVE-2024-44158: Kirin (@Pwnrin)<\/p>\n<p>Shortcuts<br \/>Available for: iPhone XS and later, iPad Pro 13-inch, iPad Pro 12.9-inch<br \/>2nd generation and later, iPad Pro 10.5-inch, iPad Pro 11-inch 1st<br \/>generation and later, iPad Air 3rd generation and later, iPad 6th<br \/>generation and later, and iPad mini 5th generation and later<br \/>Impact: An app may be able to observe data displayed to the user by<br \/>Shortcuts<br \/>Description: A privacy issue was addressed with improved handling of<br \/>temporary files.<br \/>CVE-2024-40844: Kirin (@Pwnrin) and luckyu (@uuulucky) of NorthSea<\/p>\n<p>Sync Services<br \/>Available for: iPhone XS and later, iPad Pro 13-inch, iPad Pro 12.9-inch<br \/>2nd generation and later, iPad Pro 10.5-inch, iPad Pro 11-inch 1st<br \/>generation and later, iPad Air 3rd generation and later, iPad 6th<br \/>generation and later, and iPad mini 5th generation and later<br \/>Impact: An app may be able to bypass Privacy preferences<br \/>Description: This issue was addressed with improved checks.<br \/>CVE-2024-44164: Mickey Jin (@patch1t)<\/p>\n<p>Transparency<br \/>Available for: iPhone XS and later, iPad Pro 13-inch, iPad Pro 12.9-inch<br \/>2nd generation and later, iPad Pro 10.5-inch, iPad Pro 11-inch 1st<br \/>generation and later, iPad Air 3rd generation and later, iPad 6th<br \/>generation and later, and iPad mini 5th generation and later<br \/>Impact: An app may be able to access user-sensitive data<br \/>Description: A permissions issue was addressed with additional<br \/>restrictions.<br \/>CVE-2024-44184: Bohdan Stasiuk (@Bohdan_Stasiuk)<\/p>\n<p>UIKit<br \/>Available for: iPhone XS and later, iPad Pro 13-inch, iPad Pro 12.9-inch<br \/>2nd generation and later, iPad Pro 10.5-inch, iPad Pro 11-inch 1st<br \/>generation and later, iPad Air 3rd generation and later, iPad 6th<br \/>generation and later, and iPad mini 5th generation and later<br \/>Impact: An attacker may be able to cause unexpected app termination<br \/>Description: The issue was addressed with improved bounds checks.<br \/>CVE-2024-27879: Justin Cohen<\/p>\n<p>This update is available through iTunes and Software Update on your<br \/>iOS device, and will not appear in your computer&#8217;s Software Update<br \/>application, or in the Apple Downloads site. Make sure you have an<br \/>Internet connection and have installed the latest version of iTunes<br \/>from https:\/\/www.apple.com\/itunes\/<\/p>\n<p>iTunes and Software Update on the device will automatically check<br \/>Apple&#8217;s update server on its weekly schedule. When an update is<br \/>detected, it is downloaded and the option to be installed is<br \/>presented to the user when the iOS device is docked. We recommend<br \/>applying the update immediately if possible. Selecting<br \/>Don&#8217;t Install will present the option the next time you connect<br \/>your iOS device.<\/p>\n<p>The automatic update process may take up to a week depending on<br \/>the day that iTunes or the device checks for updates. You may<br \/>manually obtain the update via the Check for Updates button<br \/>within iTunes, or the Software Update on your device.<\/p>\n<p>To check that the iPhone, iPod touch, or iPad has been updated:<\/p>\n<p>* Navigate to Settings<br \/>* Select General<br \/>* Select About. The version after applying this update will be<br \/>&#8220;iOS 17.7 and iPadOS 17.7&#8221;.<\/p>\n<p>All information is also posted on the Apple Security Releases<br \/>web site: https:\/\/support.apple.com\/100100.<\/p>\n<p>This message is signed with Apple&#8217;s Product Security PGP key,<br \/>and details are available at:<br \/>https:\/\/www.apple.com\/support\/security\/pgp\/<\/p>\n<p>&#8212;&#8211;BEGIN PGP SIGNATURE&#8212;&#8211;<\/p>\n<p>iQIzBAEBCAAdFiEEsz9altA7uTI+rE\/qX+5d1TXaIvoFAmbo1AEACgkQX+5d1TXa<br \/>Ivr0LBAAn28J4FgN4GG7wRGwiXT2GIy0vuGDc8bbNiezEqpkSL1XtjFl0e4ChhtB<br \/>7VWnEhCd2yq\/6iy7yak3EiKuYngQZ79O3dBERviNFgM5pK8hxX46WR3K\/M69U9iO<br \/>szkmaOOE81mTiAKCjy4MP8qMsvHY79ZA0r9Bl2aJCQJMAscs4mQ+Gfy2OAWDHKrG<br \/>d1iapLxp2jQRVDlguKL8slJDIql3LD2anZ\/4qob9cnE9b2z0g0r8Iv\/vjlZXdOse<br \/>Gx7TqQ\/kWlg6rBHf9KhSjr+ipFfvFYJ9O+QCAcwgtilPkRmD4q3MiCZqG234qhmB<br \/>4ZVrW3NrJQVR4ACF8e+tnB79pcXeVMvhytpUdY+fAxffihkbLzIydI5EriuAvtpi<br \/>tmI3hwqLwJBwHOSDroCOs6kIkDL4RXVCSkIuwiRfa\/hWxVJE9lYQxUCH7vR4Komr<br \/>wnuB7hhN3oqeRgXqtB1HcJ8Elu3KnA8rebF1X1TcMqTc5LbqZwCPDOAU07HfTVBa<br \/>xWlLh0NfmXq2JIE+yozNTOySEvggfYiXL5JopRXocF0YWne63OoA0vhvljQhEClQ<br \/>RQifB4daPnmyxxJOWFhqY8dMcnrfb0xXB5OyxZFG1AiGLjg5qaSQYMAZoJvImuTV<br \/>wFSKuKBHs7ahXn7EVojoe7m9WEiRqCXiORHmT6BF3vmWidni5Xs=<br \/>=J1rf<br \/>&#8212;&#8211;END PGP SIGNATURE&#8212;&#8211;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>&#8212;&#8211;BEGIN PGP SIGNED MESSAGE&#8212;&#8211;Hash: SHA256 APPLE-SA-09-16-2024-8 iOS 17.7 and iPadOS 17.7 iOS 17.7 and iPadOS 17.7 addresses the following issues.Information about the security content is also available athttps:\/\/support.apple.com\/121246. Apple maintains a Security Releases page athttps:\/\/support.apple.com\/100100 which lists recentsoftware updates with security advisories. AccessibilityAvailable for: iPhone XS and later, iPad Pro 13-inch, iPad Pro 12.9-inch2nd generation &hellip;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[26],"tags":[],"class_list":["post-59765","post","type-post","status-publish","format-standard","hentry","category-vulnerability"],"_links":{"self":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts\/59765","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/comments?post=59765"}],"version-history":[{"count":0,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts\/59765\/revisions"}],"wp:attachment":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/media?parent=59765"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/categories?post=59765"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/tags?post=59765"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}