{"id":59982,"date":"2024-10-30T03:36:05","date_gmt":"2024-10-30T00:36:05","guid":{"rendered":"https:\/\/packetstormsecurity.com\/files\/182364\/APPLE-SA-10-28-2024-5.txt"},"modified":"2024-10-30T03:36:05","modified_gmt":"2024-10-30T00:36:05","slug":"apple-security-advisory-10-28-2024-5","status":"publish","type":"post","link":"https:\/\/afaghhosting.net\/blog\/apple-security-advisory-10-28-2024-5\/","title":{"rendered":"Apple Security Advisory 10-28-2024-5"},"content":{"rendered":"<p>&#8212;&#8211;BEGIN PGP SIGNED MESSAGE&#8212;&#8211;<br \/>Hash: SHA256<\/p>\n<p>APPLE-SA-10-28-2024-5 macOS Ventura 13.7.1<\/p>\n<p>macOS Ventura 13.7.1 addresses the following issues.<br \/>Information about the security content is also available at<br \/>https:\/\/support.apple.com\/121568.<\/p>\n<p>Apple maintains a Security Releases page at<br \/>https:\/\/support.apple.com\/100100 which lists recent<br \/>software updates with security advisories.<\/p>\n<p>App Support<br \/>Available for: macOS Ventura<br \/>Impact: A malicious app may be able to run arbitrary shortcuts without<br \/>user consent<br \/>Description: A path handling issue was addressed with improved logic.<br \/>CVE-2024-44255: an anonymous researcher<\/p>\n<p>AppleMobileFileIntegrity<br \/>Available for: macOS Ventura<br \/>Impact: A sandboxed process may be able to circumvent sandbox<br \/>restrictions<br \/>Description: A logic issue was addressed with improved validation.<br \/>CVE-2024-44270: Mickey Jin (@patch1t)<\/p>\n<p>AppleMobileFileIntegrity<br \/>Available for: macOS Ventura<br \/>Impact: An app may be able to modify protected parts of the file system<br \/>Description: A downgrade issue affecting Intel-based Mac computers was<br \/>addressed with additional code-signing restrictions.<br \/>CVE-2024-44280: Mickey Jin (@patch1t)<\/p>\n<p>ARKit<br \/>Available for: macOS Ventura<br \/>Impact: Processing a maliciously crafted file may lead to heap<br \/>corruption<br \/>Description: The issue was addressed with improved checks.<br \/>CVE-2024-44126: Holger Fuhrmannek<\/p>\n<p>Assets<br \/>Available for: macOS Ventura<br \/>Impact: A malicious app with root privileges may be able to modify the<br \/>contents of system files<br \/>Description: This issue was addressed by removing the vulnerable code.<br \/>CVE-2024-44260: Mickey Jin (@patch1t)<\/p>\n<p>CoreServicesUIAgent<br \/>Available for: macOS Ventura<br \/>Impact: An app may be able to modify protected parts of the file system<br \/>Description: This issue was addressed with additional entitlement<br \/>checks.<br \/>CVE-2024-44295: an anonymous researcher<\/p>\n<p>CoreText<br \/>Available for: macOS Ventura<br \/>Impact: Processing a maliciously crafted font may result in the<br \/>disclosure of process memory<br \/>Description: The issue was addressed with improved checks.<br \/>CVE-2024-44240: Hossein Lotfi (@hosselot) of Trend Micro Zero Day<br \/>Initiative<br \/>CVE-2024-44302: Hossein Lotfi (@hosselot) of Trend Micro Zero Day<br \/>Initiative<\/p>\n<p>CUPS<br \/>Available for: macOS Ventura<br \/>Impact: An attacker in a privileged network position may be able to leak<br \/>sensitive user information<br \/>Description: An issue existed in the parsing of URLs. This issue was<br \/>addressed with improved input validation.<br \/>CVE-2024-44213: Alexandre Bedard<\/p>\n<p>DiskArbitration<br \/>Available for: macOS Ventura<br \/>Impact: A sandboxed app may be able to access sensitive user data<br \/>Description: The issue was addressed with improved checks.<br \/>CVE-2024-40855: Csaba Fitzl (@theevilbit) of Kandji<\/p>\n<p>Find My<br \/>Available for: macOS Ventura<br \/>Impact: An app may be able to read sensitive location information<br \/>Description: A privacy issue was addressed with improved private data<br \/>redaction for log entries.<br \/>CVE-2024-44289: Kirin (@Pwnrin)<\/p>\n<p>Foundation<br \/>Available for: macOS Ventura<br \/>Impact: Parsing a file may lead to disclosure of user information<br \/>Description: An out-of-bounds read was addressed with improved input<br \/>validation.<br \/>CVE-2024-44282: Hossein Lotfi (@hosselot) of Trend Micro Zero Day<br \/>Initiative<\/p>\n<p>Game Controllers<br \/>Available for: macOS Ventura<br \/>Impact: An attacker with physical access can input Game Controller<br \/>events to apps running on a locked device<br \/>Description: The issue was addressed by restricting options offered on a<br \/>locked device.<br \/>CVE-2024-44265: Ronny Stiftel<\/p>\n<p>ImageIO<br \/>Available for: macOS Ventura<br \/>Impact: Processing an image may result in disclosure of process memory<br \/>Description: This issue was addressed with improved checks.<br \/>CVE-2024-44215: Junsung Lee working with Trend Micro Zero Day Initiative<\/p>\n<p>ImageIO<br \/>Available for: macOS Ventura<br \/>Impact: Processing a maliciously crafted message may lead to a denial-<br \/>of-service<br \/>Description: The issue was addressed with improved bounds checks.<br \/>CVE-2024-44297: Jex Amro<\/p>\n<p>Installer<br \/>Available for: macOS Ventura<br \/>Impact: An app may be able to access user-sensitive data<br \/>Description: An access issue was addressed with additional sandbox<br \/>restrictions.<br \/>CVE-2024-44216: Zhongquan Li (@Guluisacat)<\/p>\n<p>Installer<br \/>Available for: macOS Ventura<br \/>Impact: A malicious application may be able to modify protected parts of<br \/>the file system<br \/>Description: The issue was addressed with improved checks.<br \/>CVE-2024-44287: Mickey Jin (@patch1t)<\/p>\n<p>IOGPUFamily<br \/>Available for: macOS Ventura<br \/>Impact: A malicious app may be able to cause a denial-of-service<br \/>Description: The issue was addressed with improved memory handling.<br \/>CVE-2024-44197: Wang Yu of Cyberserval<\/p>\n<p>Kernel<br \/>Available for: macOS Ventura<br \/>Impact: An app may be able to leak sensitive kernel state<br \/>Description: An information disclosure issue was addressed with improved<br \/>private data redaction for log entries.<br \/>CVE-2024-44239: Mateusz Krzywicki (@krzywix)<\/p>\n<p>LaunchServices<br \/>Available for: macOS Ventura<br \/>Impact: An application may be able to break out of its sandbox<br \/>Description: A logic issue was addressed with improved checks.<br \/>CVE-2024-44122: an anonymous researcher<\/p>\n<p>Maps<br \/>Available for: macOS Ventura<br \/>Impact: An app may be able to read sensitive location information<br \/>Description: This issue was addressed with improved redaction of<br \/>sensitive information.<br \/>CVE-2024-44222: Kirin (@Pwnrin)<\/p>\n<p>Messages<br \/>Available for: macOS Ventura<br \/>Impact: An app may be able to break out of its sandbox<br \/>Description: The issue was addressed with improved input sanitization.<br \/>CVE-2024-44256: Mickey Jin (@patch1t)<\/p>\n<p>PackageKit<br \/>Available for: macOS Ventura<br \/>Impact: An app may be able to bypass Privacy preferences<br \/>Description: A path deletion vulnerability was addressed by preventing<br \/>vulnerable code from running with privileges.<br \/>CVE-2024-44156: Arsenii Kostromin (0x3c3e)<br \/>CVE-2024-44159: Mickey Jin (@patch1t)<\/p>\n<p>PackageKit<br \/>Available for: macOS Ventura<br \/>Impact: An app may be able to modify protected parts of the file system<br \/>Description: A permissions issue was addressed with additional<br \/>restrictions.<br \/>CVE-2024-44196: Csaba Fitzl (@theevilbit) of Kandji<\/p>\n<p>PackageKit<br \/>Available for: macOS Ventura<br \/>Impact: An app may be able to modify protected parts of the file system<br \/>Description: The issue was addressed with improved checks.<br \/>CVE-2024-44253: Mickey Jin (@patch1t), Csaba Fitzl (@theevilbit) of<br \/>Kandji<\/p>\n<p>PackageKit<br \/>Available for: macOS Ventura<br \/>Impact: A malicious application may be able to modify protected parts of<br \/>the file system<br \/>Description: The issue was addressed with improved checks.<br \/>CVE-2024-44247: Un3xploitable of CW Research Inc<br \/>CVE-2024-44267: Bohdan Stasiuk (@Bohdan_Stasiuk), Un3xploitable of CW<br \/>Research Inc, Pedro T\u00f4rres (@t0rr3sp3dr0)<br \/>CVE-2024-44301: Bohdan Stasiuk (@Bohdan_Stasiuk), Un3xploitable of CW<br \/>Research Inc, Pedro T\u00f4rres (@t0rr3sp3dr0)<br \/>CVE-2024-44275: Arsenii Kostromin (0x3c3e)<\/p>\n<p>PackageKit<br \/>Available for: macOS Ventura<br \/>Impact: An attacker with root privileges may be able to delete protected<br \/>system files<br \/>Description: A path deletion vulnerability was addressed by preventing<br \/>vulnerable code from running with privileges.<br \/>CVE-2024-44294: Mickey Jin (@patch1t)<\/p>\n<p>Screen Capture<br \/>Available for: macOS Ventura<br \/>Impact: An attacker with physical access may be able to share items from<br \/>the lock screen<br \/>Description: The issue was addressed with improved checks.<br \/>CVE-2024-44137: Halle Winkler, Politepix @hallewinkler<\/p>\n<p>Shortcuts<br \/>Available for: macOS Ventura<br \/>Impact: An app may be able to access sensitive user data<br \/>Description: This issue was addressed with improved redaction of<br \/>sensitive information.<br \/>CVE-2024-44254: Kirin (@Pwnrin)<\/p>\n<p>Shortcuts<br \/>Available for: macOS Ventura<br \/>Impact: A malicious app may use shortcuts to access restricted files<br \/>Description: A logic issue was addressed with improved checks.<br \/>CVE-2024-44269: an anonymous researcher<\/p>\n<p>sips<br \/>Available for: macOS Ventura<br \/>Impact: Processing a maliciously crafted file may lead to unexpected app<br \/>termination<br \/>Description: An out-of-bounds access issue was addressed with improved<br \/>bounds checking.<br \/>CVE-2024-44236: Hossein Lotfi (@hosselot) of Trend Micro Zero Day<br \/>Initiative<br \/>CVE-2024-44237: Hossein Lotfi (@hosselot) of Trend Micro Zero Day<br \/>Initiative<\/p>\n<p>sips<br \/>Available for: macOS Ventura<br \/>Impact: Parsing a maliciously crafted file may lead to an unexpected app<br \/>termination<br \/>Description: An out-of-bounds write issue was addressed with improved<br \/>input validation.<br \/>CVE-2024-44284: Junsung Lee, dw0r! working with Trend Micro Zero Day<br \/>Initiative<\/p>\n<p>sips<br \/>Available for: macOS Ventura<br \/>Impact: Parsing a file may lead to disclosure of user information<br \/>Description: An out-of-bounds read was addressed with improved input<br \/>validation.<br \/>CVE-2024-44279: Hossein Lotfi (@hosselot) of Trend Micro Zero Day<br \/>Initiative<br \/>CVE-2024-44281: Hossein Lotfi (@hosselot) of Trend Micro Zero Day<br \/>Initiative<\/p>\n<p>sips<br \/>Available for: macOS Ventura<br \/>Impact: Parsing a maliciously crafted file may lead to an unexpected app<br \/>termination<br \/>Description: An out-of-bounds read was addressed with improved bounds<br \/>checking.<br \/>CVE-2024-44283: Hossein Lotfi (@hosselot) of Trend Micro Zero Day<br \/>Initiative<\/p>\n<p>Siri<br \/>Available for: macOS Ventura<br \/>Impact: A sandboxed app may be able to access sensitive user data in<br \/>system logs<br \/>Description: An information disclosure issue was addressed with improved<br \/>private data redaction for log entries.<br \/>CVE-2024-44278: Kirin (@Pwnrin)<\/p>\n<p>SystemMigration<br \/>Available for: macOS Ventura<br \/>Impact: A malicious app may be able to create symlinks to protected<br \/>regions of the disk<br \/>Description: This issue was addressed with improved validation of<br \/>symlinks.<br \/>CVE-2024-44264: Mickey Jin (@patch1t)<\/p>\n<p>WindowServer<br \/>Available for: macOS Ventura<br \/>Impact: An app may be able to access sensitive user data<br \/>Description: This issue was addressed with improved redaction of<br \/>sensitive information.<br \/>CVE-2024-44257: Bohdan Stasiuk (@Bohdan_Stasiuk)<\/p>\n<p>Additional recognition<\/p>\n<p>NetworkExtension<br \/>We would like to acknowledge Patrick Wardle of DoubleYou &amp; the<br \/>Objective-See Foundation for their assistance.<\/p>\n<p>Security<br \/>We would like to acknowledge Bing Shi, Wenchao Li and Xiaolong Bai of<br \/>Alibaba Group for their assistance.<\/p>\n<p>Spotlight<br \/>We would like to acknowledge Paulo Henrique Batista Rosa de Castro<br \/>(@paulohbrc) for their assistance.<\/p>\n<p>macOS Ventura 13.7.1 may be obtained from the Mac App Store or<br \/>Apple&#8217;s Software Downloads web site:<br \/>https:\/\/support.apple.com\/downloads\/<\/p>\n<p>All information is also posted on the Apple Security Releases<br \/>web site: https:\/\/support.apple.com\/100100.<\/p>\n<p>This message is signed with Apple&#8217;s Product Security PGP key,<br \/>and details are available at:<br \/>https:\/\/www.apple.com\/support\/security\/pgp\/<\/p>\n<p>&#8212;&#8211;BEGIN PGP SIGNATURE&#8212;&#8211;<\/p>\n<p>iQIzBAEBCAAdFiEEsz9altA7uTI+rE\/qX+5d1TXaIvoFAmcgAA8ACgkQX+5d1TXa<br \/>IvrXBg\/8DeQSQAigpeRoMRWyyfrezV21cUXKEUCAjoJhrdQmSg37fyGZNPeWsSxQ<br \/>gGqvh8sGPaI6iKFpd2hY9a9CyJGnBmH0AwjeU0evvmqclrQaYEuHZosaR1yyiemt<br \/>wjTAt9IvtaT0oLJ4ic+pdu4jXgc\/pbzg25bwNbzG7S\/pMFs\/by7yAJt9duOGFkMC<br \/>5FuLFdpASL1uZ3Mh3o1tIxexLV+UBv2duTdYhJSKDTvD9GDZ4KLKlcujt1XnF76o<br \/>uu7TPx7mh6oZwTk\/1nhZqkIlaJyJPKv7Qf+za6FfEjpw+jU8QNnQQFPIq2wc1qR3<br \/>rzsbDubRoTPt0a59Q3z2sbDlRxk3Phuq6o58PJS+FcAEOqCSeChNIDDMoFvSKs7M<br \/>MdxFHtyVDhUPyaJMyjnzpOTqxCn2yxbdgg1fgP5PiWeyK963zmpgnSmm\/Rqrtj4Y<br \/>Y0ObbeKn4MArTc+7vMSJb\/f2WtsJPn5MufpUPNhXp2OTdXOVEoa+MIO+BDHc+32d<br \/>AXnwXLWEec7FnSILyWTd+lApPKy4+ptn1asnDrhz1s3VuGC27mImtxh0kn9JUfFT<br \/>kFXX9ct8G2AybkxOLMYmen5fb\/33Ypbb1AJp7n0776d1qpomsIUdSkEJs7\/CAIcb<br \/>vWc21lLZdoaYfd7KmL\/9Y\/n0S5AihmqXmsDQKQ4+lrxJmU4xww0=<br \/>=cN79<br \/>&#8212;&#8211;END PGP SIGNATURE&#8212;&#8211;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>&#8212;&#8211;BEGIN PGP SIGNED MESSAGE&#8212;&#8211;Hash: SHA256 APPLE-SA-10-28-2024-5 macOS Ventura 13.7.1 macOS Ventura 13.7.1 addresses the following issues.Information about the security content is also available athttps:\/\/support.apple.com\/121568. Apple maintains a Security Releases page athttps:\/\/support.apple.com\/100100 which lists recentsoftware updates with security advisories. App SupportAvailable for: macOS VenturaImpact: A malicious app may be able to run arbitrary shortcuts withoutuser consentDescription: &hellip;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[26],"tags":[],"class_list":["post-59982","post","type-post","status-publish","format-standard","hentry","category-vulnerability"],"_links":{"self":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts\/59982","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/comments?post=59982"}],"version-history":[{"count":0,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts\/59982\/revisions"}],"wp:attachment":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/media?parent=59982"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/categories?post=59982"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/tags?post=59982"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}