{"id":59981,"date":"2024-10-30T02:30:00","date_gmt":"2024-10-29T23:30:00","guid":{"rendered":"https:\/\/packetstormsecurity.com\/files\/182365\/APPLE-SA-10-28-2024-6.txt"},"modified":"2024-10-30T02:30:00","modified_gmt":"2024-10-29T23:30:00","slug":"apple-security-advisory-10-28-2024-6","status":"publish","type":"post","link":"https:\/\/afaghhosting.net\/blog\/apple-security-advisory-10-28-2024-6\/","title":{"rendered":"Apple Security Advisory 10-28-2024-6"},"content":{"rendered":"<p>&#8212;&#8211;BEGIN PGP SIGNED MESSAGE&#8212;&#8211;<br \/>Hash: SHA256<\/p>\n<p>APPLE-SA-10-28-2024-6 watchOS 11.1<\/p>\n<p>watchOS 11.1 addresses the following issues.<br \/>Information about the security content is also available at<br \/>https:\/\/support.apple.com\/121565.<\/p>\n<p>Apple maintains a Security Releases page at<br \/>https:\/\/support.apple.com\/100100 which lists recent<br \/>software updates with security advisories.<\/p>\n<p>Accessibility<br \/>Available for: Apple Watch Series 6 and later<br \/>Impact: An attacker with physical access to a locked device may be able<br \/>to view sensitive user information<br \/>Description: The issue was addressed with improved authentication.<br \/>CVE-2024-44274: Rizki Maulana (rmrizki.my.id), Matthew Butler, Jake<br \/>Derouin<\/p>\n<p>App Support<br \/>Available for: Apple Watch Series 6 and later<br \/>Impact: A malicious app may be able to run arbitrary shortcuts without<br \/>user consent<br \/>Description: A path handling issue was addressed with improved logic.<br \/>CVE-2024-44255: an anonymous researcher<\/p>\n<p>CoreMedia Playback<br \/>Available for: Apple Watch Series 6 and later<br \/>Impact: A malicious app may be able to access private information<br \/>Description: This issue was addressed with improved handling of<br \/>symlinks.<br \/>CVE-2024-44273: pattern-f (@pattern_F_), Hikerell of Loadshine Lab<\/p>\n<p>CoreText<br \/>Available for: Apple Watch Series 6 and later<br \/>Impact: Processing a maliciously crafted font may result in the<br \/>disclosure of process memory<br \/>Description: The issue was addressed with improved checks.<br \/>CVE-2024-44240: Hossein Lotfi (@hosselot) of Trend Micro Zero Day<br \/>Initiative<br \/>CVE-2024-44302: Hossein Lotfi (@hosselot) of Trend Micro Zero Day<br \/>Initiative<\/p>\n<p>Foundation<br \/>Available for: Apple Watch Series 6 and later<br \/>Impact: Parsing a file may lead to disclosure of user information<br \/>Description: An out-of-bounds read was addressed with improved input<br \/>validation.<br \/>CVE-2024-44282: Hossein Lotfi (@hosselot) of Trend Micro Zero Day<br \/>Initiative<\/p>\n<p>ImageIO<br \/>Available for: Apple Watch Series 6 and later<br \/>Impact: Processing an image may result in disclosure of process memory<br \/>Description: This issue was addressed with improved checks.<br \/>CVE-2024-44215: Junsung Lee working with Trend Micro Zero Day Initiative<\/p>\n<p>ImageIO<br \/>Available for: Apple Watch Series 6 and later<br \/>Impact: Processing a maliciously crafted message may lead to a denial-<br \/>of-service<br \/>Description: The issue was addressed with improved bounds checks.<br \/>CVE-2024-44297: Jex Amro<\/p>\n<p>IOSurface<br \/>Available for: Apple Watch Series 6 and later<br \/>Impact: An app may be able to cause unexpected system termination or<br \/>corrupt kernel memory<br \/>Description: A use-after-free issue was addressed with improved memory<br \/>management.<br \/>CVE-2024-44285: an anonymous researcher<\/p>\n<p>Kernel<br \/>Available for: Apple Watch Series 6 and later<br \/>Impact: An app may be able to leak sensitive kernel state<br \/>Description: An information disclosure issue was addressed with improved<br \/>private data redaction for log entries.<br \/>CVE-2024-44239: Mateusz Krzywicki (@krzywix)<\/p>\n<p>Shortcuts<br \/>Available for: Apple Watch Series 6 and later<br \/>Impact: An app may be able to access sensitive user data<br \/>Description: This issue was addressed with improved redaction of<br \/>sensitive information.<br \/>CVE-2024-44254: Kirin (@Pwnrin)<\/p>\n<p>Shortcuts<br \/>Available for: Apple Watch Series 6 and later<br \/>Impact: A malicious app may use shortcuts to access restricted files<br \/>Description: A logic issue was addressed with improved checks.<br \/>CVE-2024-44269: an anonymous researcher<\/p>\n<p>Siri<br \/>Available for: Apple Watch Series 6 and later<br \/>Impact: An app may be able to access sensitive user data<br \/>Description: This issue was addressed with improved redaction of<br \/>sensitive information.<br \/>CVE-2024-44194: Rodolphe Brunetti (@eisw0lf)<\/p>\n<p>Siri<br \/>Available for: Apple Watch Series 6 and later<br \/>Impact: A sandboxed app may be able to access sensitive user data in<br \/>system logs<br \/>Description: An information disclosure issue was addressed with improved<br \/>private data redaction for log entries.<br \/>CVE-2024-44278: Kirin (@Pwnrin)<\/p>\n<p>WebKit<br \/>Available for: Apple Watch Series 6 and later<br \/>Impact: Processing maliciously crafted web content may prevent Content<br \/>Security Policy from being enforced<br \/>Description: The issue was addressed with improved checks.<br \/>WebKit Bugzilla: 278765<br \/>CVE-2024-44296: Narendra Bhati, Manager of Cyber Security at Suma Soft<br \/>Pvt. Ltd, Pune (India)<\/p>\n<p>WebKit<br \/>Available for: Apple Watch Series 6 and later<br \/>Impact: Processing maliciously crafted web content may lead to an<br \/>unexpected process crash<br \/>Description: A memory corruption issue was addressed with improved input<br \/>validation.<br \/>WebKit Bugzilla: 279780<br \/>CVE-2024-44244: an anonymous researcher, Q1IQ (@q1iqF) and P1umer<br \/>(@p1umer)<\/p>\n<p>Additional recognition<\/p>\n<p>Calculator<br \/>We would like to acknowledge Kenneth Chew for their assistance.<\/p>\n<p>Calendar<br \/>We would like to acknowledge K\u5b9d(@Pwnrin) for their assistance.<\/p>\n<p>ImageIO<br \/>We would like to acknowledge Amir Bazine and Karsten K\u00f6nig of<br \/>CrowdStrike Counter Adversary Operations, an anonymous researcher for<br \/>their assistance.<\/p>\n<p>Messages<br \/>We would like to acknowledge Collin Potter, an anonymous researcher for<br \/>their assistance.<\/p>\n<p>NetworkExtension<br \/>We would like to acknowledge Patrick Wardle of DoubleYou &amp; the<br \/>Objective-See Foundation for their assistance.<\/p>\n<p>Photos<br \/>We would like to acknowledge James Robertson for their assistance.<\/p>\n<p>Security<br \/>We would like to acknowledge Bing Shi, Wenchao Li and Xiaolong Bai of<br \/>Alibaba Group for their assistance.<\/p>\n<p>Siri<br \/>We would like to acknowledge Bistrit Dahal for their assistance.<\/p>\n<p>Instructions on how to update your Apple Watch software are<br \/>available at https:\/\/support.apple.com\/108926<\/p>\n<p>To check the version on your Apple Watch, open the Apple Watch app<br \/>on your iPhone and select &#8220;My Watch &gt; General &gt; About&#8221;.<\/p>\n<p>Alternatively, on your watch, select &#8220;My Watch &gt; General &gt; About&#8221;.<\/p>\n<p>All information is also posted on the Apple Security Releases<br \/>web site: https:\/\/support.apple.com\/100100.<\/p>\n<p>This message is signed with Apple&#8217;s Product Security PGP key,<br \/>and details are available at:<br \/>https:\/\/www.apple.com\/support\/security\/pgp\/<\/p>\n<p>&#8212;&#8211;BEGIN PGP SIGNATURE&#8212;&#8211;<\/p>\n<p>iQIzBAEBCAAdFiEEsz9altA7uTI+rE\/qX+5d1TXaIvoFAmcgAEsACgkQX+5d1TXa<br \/>IvpYqw\/\/e5YtWRJMacUQbK4oainyrTgy1EkXT3mV7zHSmzfMYOrhfGVd\/4yKMsaa<br \/>PSrREy9rcN\/oQdLulbAhDfqzEmHSczIxWeP4J48xSR6Od\/PY9KFdg4tUJ\/DjWp62<br \/>LgvsxyOY6HFt5vvzh0Cguf7xjskHgHKAgX+PbByT\/RNLEOk8Q4F3acKyq1D3oGH4<br \/>5yRBHkNyY2rpJtu\/6wrxKrn5+H\/OFDcO9ABp772nGm75pa1aaxuLlocVdOezZAod<br \/>uWmApZDfLns3wh5yBBuGd9XfXMlpKE0zl1i8y6bPDqe9DBYvS8j0fnZGKNURUaBV<br \/>yIPYJi1IH8V0jTYhnwUN0bTYE1IrEYU1sUSDEcq4vBmSxPxXZmY2sgcIjnEgJY8Q<br \/>d0f1tzd\/C0qPYAIpRIFj8bpgbN22uDEVbT58dh+idhg6c+tckQnGEmadPg9c9H\/m<br \/>\/QxJcc5LdMMwOmyBTSNbwykvb6GKO5TLec1PhU\/SImSXxAmtLwNWPk72tZpWEZiI<br \/>ASKal+XcCa\/SO3Fyfh+VhhbjmJIdR9wki2R+DXUcwfktOVKb4GWMDWPv6KiRL4ls<br \/>cNudvcc409JBnIJpKAojXcmzPdqWlICbrPTHihyO9Vf7tIRcgxpBaX8YgYy+lyO4<br \/>3kzUGycxUi4kqHao38ag7xNANdHQxO1VTamYDJLYCEXi62kuxno=<br \/>=7KV0<br \/>&#8212;&#8211;END PGP SIGNATURE&#8212;&#8211;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>&#8212;&#8211;BEGIN PGP SIGNED MESSAGE&#8212;&#8211;Hash: SHA256 APPLE-SA-10-28-2024-6 watchOS 11.1 watchOS 11.1 addresses the following issues.Information about the security content is also available athttps:\/\/support.apple.com\/121565. Apple maintains a Security Releases page athttps:\/\/support.apple.com\/100100 which lists recentsoftware updates with security advisories. AccessibilityAvailable for: Apple Watch Series 6 and laterImpact: An attacker with physical access to a locked device may be &hellip;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[26],"tags":[],"class_list":["post-59981","post","type-post","status-publish","format-standard","hentry","category-vulnerability"],"_links":{"self":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts\/59981","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/comments?post=59981"}],"version-history":[{"count":0,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts\/59981\/revisions"}],"wp:attachment":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/media?parent=59981"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/categories?post=59981"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/tags?post=59981"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}