{"id":59983,"date":"2024-10-30T04:44:48","date_gmt":"2024-10-30T01:44:48","guid":{"rendered":"https:\/\/packetstormsecurity.com\/files\/182363\/APPLE-SA-10-28-2024-4.txt"},"modified":"2024-10-30T04:44:48","modified_gmt":"2024-10-30T01:44:48","slug":"apple-security-advisory-10-28-2024-4","status":"publish","type":"post","link":"https:\/\/afaghhosting.net\/blog\/apple-security-advisory-10-28-2024-4\/","title":{"rendered":"Apple Security Advisory 10-28-2024-4"},"content":{"rendered":"<p>&#8212;&#8211;BEGIN PGP SIGNED MESSAGE&#8212;&#8211;<br \/>Hash: SHA256<\/p>\n<p>APPLE-SA-10-28-2024-4 macOS Sonoma 14.7.1<\/p>\n<p>macOS Sonoma 14.7.1 addresses the following issues.<br \/>Information about the security content is also available at<br \/>https:\/\/support.apple.com\/121570.<\/p>\n<p>Apple maintains a Security Releases page at<br \/>https:\/\/support.apple.com\/100100 which lists recent<br \/>software updates with security advisories.<\/p>\n<p>App Support<br \/>Available for: macOS Sonoma<br \/>Impact: A malicious app may be able to run arbitrary shortcuts without<br \/>user consent<br \/>Description: A path handling issue was addressed with improved logic.<br \/>CVE-2024-44255: an anonymous researcher<\/p>\n<p>AppleMobileFileIntegrity<br \/>Available for: macOS Sonoma<br \/>Impact: A sandboxed process may be able to circumvent sandbox<br \/>restrictions<br \/>Description: A logic issue was addressed with improved validation.<br \/>CVE-2024-44270: Mickey Jin (@patch1t)<\/p>\n<p>AppleMobileFileIntegrity<br \/>Available for: macOS Sonoma<br \/>Impact: An app may be able to modify protected parts of the file system<br \/>Description: A downgrade issue affecting Intel-based Mac computers was<br \/>addressed with additional code-signing restrictions.<br \/>CVE-2024-44280: Mickey Jin (@patch1t)<\/p>\n<p>Assets<br \/>Available for: macOS Sonoma<br \/>Impact: A malicious app with root privileges may be able to modify the<br \/>contents of system files<br \/>Description: This issue was addressed by removing the vulnerable code.<br \/>CVE-2024-44260: Mickey Jin (@patch1t)<\/p>\n<p>CoreMedia Playback<br \/>Available for: macOS Sonoma<br \/>Impact: A malicious app may be able to access private information<br \/>Description: This issue was addressed with improved handling of<br \/>symlinks.<br \/>CVE-2024-44273: pattern-f (@pattern_F_), Hikerell of Loadshine Lab<\/p>\n<p>CoreServicesUIAgent<br \/>Available for: macOS Sonoma<br \/>Impact: An app may be able to modify protected parts of the file system<br \/>Description: This issue was addressed with additional entitlement<br \/>checks.<br \/>CVE-2024-44295: an anonymous researcher<\/p>\n<p>CoreText<br \/>Available for: macOS Sonoma<br \/>Impact: Processing a maliciously crafted font may result in the<br \/>disclosure of process memory<br \/>Description: The issue was addressed with improved checks.<br \/>CVE-2024-44240: Hossein Lotfi (@hosselot) of Trend Micro Zero Day<br \/>Initiative<br \/>CVE-2024-44302: Hossein Lotfi (@hosselot) of Trend Micro Zero Day<br \/>Initiative<\/p>\n<p>CUPS<br \/>Available for: macOS Sonoma<br \/>Impact: An attacker in a privileged network position may be able to leak<br \/>sensitive user information<br \/>Description: An issue existed in the parsing of URLs. This issue was<br \/>addressed with improved input validation.<br \/>CVE-2024-44213: Alexandre Bedard<\/p>\n<p>DiskArbitration<br \/>Available for: macOS Sonoma<br \/>Impact: A sandboxed app may be able to access sensitive user data<br \/>Description: The issue was addressed with improved checks.<br \/>CVE-2024-40855: Csaba Fitzl (@theevilbit) of Kandji<\/p>\n<p>Find My<br \/>Available for: macOS Sonoma<br \/>Impact: An app may be able to read sensitive location information<br \/>Description: A privacy issue was addressed with improved private data<br \/>redaction for log entries.<br \/>CVE-2024-44289: Kirin (@Pwnrin)<\/p>\n<p>Foundation<br \/>Available for: macOS Sonoma<br \/>Impact: Parsing a file may lead to disclosure of user information<br \/>Description: An out-of-bounds read was addressed with improved input<br \/>validation.<br \/>CVE-2024-44282: Hossein Lotfi (@hosselot) of Trend Micro Zero Day<br \/>Initiative<\/p>\n<p>Game Controllers<br \/>Available for: macOS Sonoma<br \/>Impact: An attacker with physical access can input Game Controller<br \/>events to apps running on a locked device<br \/>Description: The issue was addressed by restricting options offered on a<br \/>locked device.<br \/>CVE-2024-44265: Ronny Stiftel<\/p>\n<p>ImageIO<br \/>Available for: macOS Sonoma<br \/>Impact: Processing an image may result in disclosure of process memory<br \/>Description: This issue was addressed with improved checks.<br \/>CVE-2024-44215: Junsung Lee working with Trend Micro Zero Day Initiative<\/p>\n<p>ImageIO<br \/>Available for: macOS Sonoma<br \/>Impact: Processing a maliciously crafted message may lead to a denial-<br \/>of-service<br \/>Description: The issue was addressed with improved bounds checks.<br \/>CVE-2024-44297: Jex Amro<\/p>\n<p>Installer<br \/>Available for: macOS Sonoma<br \/>Impact: An app may be able to access user-sensitive data<br \/>Description: An access issue was addressed with additional sandbox<br \/>restrictions.<br \/>CVE-2024-44216: Zhongquan Li (@Guluisacat)<\/p>\n<p>Installer<br \/>Available for: macOS Sonoma<br \/>Impact: A malicious application may be able to modify protected parts of<br \/>the file system<br \/>Description: The issue was addressed with improved checks.<br \/>CVE-2024-44287: Mickey Jin (@patch1t)<\/p>\n<p>IOGPUFamily<br \/>Available for: macOS Sonoma<br \/>Impact: A malicious app may be able to cause a denial-of-service<br \/>Description: The issue was addressed with improved memory handling.<br \/>CVE-2024-44197: Wang Yu of Cyberserval<\/p>\n<p>Kernel<br \/>Available for: macOS Sonoma<br \/>Impact: An app may be able to leak sensitive kernel state<br \/>Description: An information disclosure issue was addressed with improved<br \/>private data redaction for log entries.<br \/>CVE-2024-44239: Mateusz Krzywicki (@krzywix)<\/p>\n<p>Kernel<br \/>Available for: macOS Sonoma<br \/>Impact: An app may be able to access sensitive user data<br \/>Description: This issue was addressed with improved validation of<br \/>symlinks.<br \/>CVE-2024-44175: Csaba Fitzl (@theevilbit) of Kandji<\/p>\n<p>LaunchServices<br \/>Available for: macOS Sonoma<br \/>Impact: An application may be able to break out of its sandbox<br \/>Description: A logic issue was addressed with improved checks.<br \/>CVE-2024-44122: an anonymous researcher<\/p>\n<p>Maps<br \/>Available for: macOS Sonoma<br \/>Impact: An app may be able to read sensitive location information<br \/>Description: This issue was addressed with improved redaction of<br \/>sensitive information.<br \/>CVE-2024-44222: Kirin (@Pwnrin)<\/p>\n<p>Messages<br \/>Available for: macOS Sonoma<br \/>Impact: An app may be able to break out of its sandbox<br \/>Description: The issue was addressed with improved input sanitization.<br \/>CVE-2024-44256: Mickey Jin (@patch1t)<\/p>\n<p>PackageKit<br \/>Available for: macOS Sonoma<br \/>Impact: An app may be able to bypass Privacy preferences<br \/>Description: A path deletion vulnerability was addressed by preventing<br \/>vulnerable code from running with privileges.<br \/>CVE-2024-44159: Mickey Jin (@patch1t)<br \/>CVE-2024-44156: Arsenii Kostromin (0x3c3e)<\/p>\n<p>PackageKit<br \/>Available for: macOS Sonoma<br \/>Impact: An app may be able to modify protected parts of the file system<br \/>Description: A permissions issue was addressed with additional<br \/>restrictions.<br \/>CVE-2024-44196: Csaba Fitzl (@theevilbit) of Kandji<\/p>\n<p>PackageKit<br \/>Available for: macOS Sonoma<br \/>Impact: An app may be able to modify protected parts of the file system<br \/>Description: The issue was addressed with improved checks.<br \/>CVE-2024-44253: Mickey Jin (@patch1t), Csaba Fitzl (@theevilbit) of<br \/>Kandji<\/p>\n<p>PackageKit<br \/>Available for: macOS Sonoma<br \/>Impact: A malicious application may be able to modify protected parts of<br \/>the file system<br \/>Description: The issue was addressed with improved checks.<br \/>CVE-2024-44247: Un3xploitable of CW Research Inc<br \/>CVE-2024-44267: Bohdan Stasiuk (@Bohdan_Stasiuk), Un3xploitable of CW<br \/>Research Inc, Pedro T\u00f4rres (@t0rr3sp3dr0)<br \/>CVE-2024-44301: Bohdan Stasiuk (@Bohdan_Stasiuk), Un3xploitable of CW<br \/>Research Inc, Pedro T\u00f4rres (@t0rr3sp3dr0)<br \/>CVE-2024-44275: Arsenii Kostromin (0x3c3e)<\/p>\n<p>PackageKit<br \/>Available for: macOS Sonoma<br \/>Impact: An attacker with root privileges may be able to delete protected<br \/>system files<br \/>Description: A path deletion vulnerability was addressed by preventing<br \/>vulnerable code from running with privileges.<br \/>CVE-2024-44294: Mickey Jin (@patch1t)<\/p>\n<p>SceneKit<br \/>Available for: macOS Sonoma<br \/>Impact: Processing a maliciously crafted file may lead to unexpected app<br \/>termination<br \/>Description: A buffer overflow was addressed with improved size<br \/>validation.<br \/>CVE-2024-44144: \ub0e5\ub0e5<\/p>\n<p>SceneKit<br \/>Available for: macOS Sonoma<br \/>Impact: Processing a maliciously crafted file may lead to heap<br \/>corruption<br \/>Description: This issue was addressed with improved checks.<br \/>CVE-2024-44218: Michael DePlante (@izobashi) of Trend Micro Zero Day<br \/>Initiative<\/p>\n<p>Screen Capture<br \/>Available for: macOS Sonoma<br \/>Impact: An attacker with physical access may be able to share items from<br \/>the lock screen<br \/>Description: The issue was addressed with improved checks.<br \/>CVE-2024-44137: Halle Winkler, Politepix @hallewinkler<\/p>\n<p>Shortcuts<br \/>Available for: macOS Sonoma<br \/>Impact: An app may be able to access sensitive user data<br \/>Description: This issue was addressed with improved redaction of<br \/>sensitive information.<br \/>CVE-2024-44254: Kirin (@Pwnrin)<\/p>\n<p>Shortcuts<br \/>Available for: macOS Sonoma<br \/>Impact: A malicious app may use shortcuts to access restricted files<br \/>Description: A logic issue was addressed with improved checks.<br \/>CVE-2024-44269: an anonymous researcher<\/p>\n<p>sips<br \/>Available for: macOS Sonoma<br \/>Impact: Processing a maliciously crafted file may lead to unexpected app<br \/>termination<br \/>Description: An out-of-bounds access issue was addressed with improved<br \/>bounds checking.<br \/>CVE-2024-44236: Hossein Lotfi (@hosselot) of Trend Micro Zero Day<br \/>Initiative<br \/>CVE-2024-44237: Hossein Lotfi (@hosselot) of Trend Micro Zero Day<br \/>Initiative<\/p>\n<p>sips<br \/>Available for: macOS Sonoma<br \/>Impact: Parsing a maliciously crafted file may lead to an unexpected app<br \/>termination<br \/>Description: An out-of-bounds write issue was addressed with improved<br \/>input validation.<br \/>CVE-2024-44284: Junsung Lee, dw0r! working with Trend Micro Zero Day<br \/>Initiative<\/p>\n<p>sips<br \/>Available for: macOS Sonoma<br \/>Impact: Parsing a file may lead to disclosure of user information<br \/>Description: An out-of-bounds read was addressed with improved input<br \/>validation.<br \/>CVE-2024-44279: Hossein Lotfi (@hosselot) of Trend Micro Zero Day<br \/>Initiative<br \/>CVE-2024-44281: Hossein Lotfi (@hosselot) of Trend Micro Zero Day<br \/>Initiative<\/p>\n<p>sips<br \/>Available for: macOS Sonoma<br \/>Impact: Parsing a maliciously crafted file may lead to an unexpected app<br \/>termination<br \/>Description: An out-of-bounds read was addressed with improved bounds<br \/>checking.<br \/>CVE-2024-44283: Hossein Lotfi (@hosselot) of Trend Micro Zero Day<br \/>Initiative<\/p>\n<p>Siri<br \/>Available for: macOS Sonoma<br \/>Impact: A sandboxed app may be able to access sensitive user data in<br \/>system logs<br \/>Description: An information disclosure issue was addressed with improved<br \/>private data redaction for log entries.<br \/>CVE-2024-44278: Kirin (@Pwnrin)<\/p>\n<p>SystemMigration<br \/>Available for: macOS Sonoma<br \/>Impact: A malicious app may be able to create symlinks to protected<br \/>regions of the disk<br \/>Description: This issue was addressed with improved validation of<br \/>symlinks.<br \/>CVE-2024-44264: Mickey Jin (@patch1t)<\/p>\n<p>WindowServer<br \/>Available for: macOS Sonoma<br \/>Impact: An app may be able to access sensitive user data<br \/>Description: This issue was addressed with improved redaction of<br \/>sensitive information.<br \/>CVE-2024-44257: Bohdan Stasiuk (@Bohdan_Stasiuk)<\/p>\n<p>Additional recognition<\/p>\n<p>NetworkExtension<br \/>We would like to acknowledge Patrick Wardle of DoubleYou &amp; the<br \/>Objective-See Foundation for their assistance.<\/p>\n<p>Security<br \/>We would like to acknowledge Bing Shi, Wenchao Li and Xiaolong Bai of<br \/>Alibaba Group for their assistance.<\/p>\n<p>Spotlight<br \/>We would like to acknowledge Paulo Henrique Batista Rosa de Castro<br \/>(@paulohbrc) for their assistance.<\/p>\n<p>macOS Sonoma 14.7.1 may be obtained from the Mac App Store or Apple&#8217;s<br \/>Software Downloads web site: https:\/\/support.apple.com\/downloads\/<\/p>\n<p>All information is also posted on the Apple Security Releases<br \/>web site: https:\/\/support.apple.com\/100100.<\/p>\n<p>This message is signed with Apple&#8217;s Product Security PGP key,<br \/>and details are available at:<br \/>https:\/\/www.apple.com\/support\/security\/pgp\/<\/p>\n<p>&#8212;&#8211;BEGIN PGP SIGNATURE&#8212;&#8211;<\/p>\n<p>iQIzBAEBCAAdFiEEsz9altA7uTI+rE\/qX+5d1TXaIvoFAmcf\/9kACgkQX+5d1TXa<br \/>IvrUURAAwGoAU3ccWvDjKZw0r1ouPDWXvLoCzcHx1nQm18Usoo+GOevgBlJflGAz<br \/>i7H8nUldqtFy3YW\/Ttr0\/B0ILhPZf\/OzVmE4XqwjqNKXI5a7EvC9A9aLUjjcqNV9<br \/>JY6We0EDT+zlOfKaG1SrKhSA7Iqm7sJ6euWotsf3SaJPtVdhabi6rQzi1G5aihsq<br \/>B7w+2uLYg5ctywkwbm8Rl3XmorMIwrTrOokYhx+rZMaZwQGnB8UNrVksdaqaBQHU<br \/>ak1t71gonnGcJxhy9ceK85xk+WwlCItpUGIvWvuvLBX\/MxMZzdwIzoIP2SGNh8nV<br \/>SYYmpbdM2fpAbX0gZQBU3zPPZIoi2pyCV37sV2VIgTtjPLVYBrB2XJXPnIU8pmHA<br \/>Abrv7gE6oRY1gJHks1w3iaw8cBMhDVvFd9hr9qfCHikbKsFHfan4oYAQK4SHvxFB<br \/>N9rRrgzGcpDP6l0WT+ae\/LmLJHjJpzbu2XuNS2s6h9ohRFwyKXJ70dQku4w\/YQIV<br \/>4dciPFkiwNpd3bQpak82bPaIko\/ihLT66y6pyi+SfYDfEBgEH45VvuxhZT9+u9z0<br \/>+mxRIc+sPCD4avvt5bU\/7q\/wDIs0dAW6fjeFo8+KiM9JRPwNbTW+VPpr6QWH6JIy<br \/>BpAEQH9m0WtlqVFurN4oQWOLnO+dUYKSPYS+QZufDfsLGpO+YtY=<br \/>=LeMo<br \/>&#8212;&#8211;END PGP SIGNATURE&#8212;&#8211;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>&#8212;&#8211;BEGIN PGP SIGNED MESSAGE&#8212;&#8211;Hash: SHA256 APPLE-SA-10-28-2024-4 macOS Sonoma 14.7.1 macOS Sonoma 14.7.1 addresses the following issues.Information about the security content is also available athttps:\/\/support.apple.com\/121570. Apple maintains a Security Releases page athttps:\/\/support.apple.com\/100100 which lists recentsoftware updates with security advisories. App SupportAvailable for: macOS SonomaImpact: A malicious app may be able to run arbitrary shortcuts withoutuser consentDescription: &hellip;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[26],"tags":[],"class_list":["post-59983","post","type-post","status-publish","format-standard","hentry","category-vulnerability"],"_links":{"self":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts\/59983","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/comments?post=59983"}],"version-history":[{"count":0,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts\/59983\/revisions"}],"wp:attachment":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/media?parent=59983"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/categories?post=59983"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/tags?post=59983"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}