{"id":59984,"date":"2024-10-30T05:45:53","date_gmt":"2024-10-30T02:45:53","guid":{"rendered":"https:\/\/packetstormsecurity.com\/files\/182362\/APPLE-SA-10-28-2024-3.txt"},"modified":"2024-10-30T05:45:53","modified_gmt":"2024-10-30T02:45:53","slug":"apple-security-advisory-10-28-2024-3","status":"publish","type":"post","link":"https:\/\/afaghhosting.net\/blog\/apple-security-advisory-10-28-2024-3\/","title":{"rendered":"Apple Security Advisory 10-28-2024-3"},"content":{"rendered":"<p>&#8212;&#8211;BEGIN PGP SIGNED MESSAGE&#8212;&#8211;<br \/>Hash: SHA256<\/p>\n<p>APPLE-SA-10-28-2024-3 macOS Sequoia 15.1<\/p>\n<p>macOS Sequoia 15.1 addresses the following issues.<br \/>Information about the security content is also available at<br \/>https:\/\/support.apple.com\/121564.<\/p>\n<p>Apple maintains a Security Releases page at<br \/>https:\/\/support.apple.com\/100100 which lists recent<br \/>software updates with security advisories.<\/p>\n<p>Apache<br \/>Impact: Multiple issues existed in Apache<br \/>Description: This is a vulnerability in open source code and Apple<br \/>Software is among the affected projects. The CVE-ID was assigned by a<br \/>third party. Learn more about the issue and CVE-ID at cve.org.<br \/>CVE-2024-39573<br \/>CVE-2024-38477<br \/>CVE-2024-38476<\/p>\n<p>App Support<br \/>Available for: macOS Sequoia<br \/>Impact: A malicious app may be able to run arbitrary shortcuts without<br \/>user consent<br \/>Description: A path handling issue was addressed with improved logic.<br \/>CVE-2024-44255: an anonymous researcher<\/p>\n<p>AppleMobileFileIntegrity<br \/>Available for: macOS Sequoia<br \/>Impact: A sandboxed process may be able to circumvent sandbox<br \/>restrictions<br \/>Description: A logic issue was addressed with improved validation.<br \/>CVE-2024-44270: Mickey Jin (@patch1t)<\/p>\n<p>AppleMobileFileIntegrity<br \/>Available for: macOS Sequoia<br \/>Impact: An app may be able to modify protected parts of the file system<br \/>Description: A downgrade issue affecting Intel-based Mac computers was<br \/>addressed with additional code-signing restrictions.<br \/>CVE-2024-44280: Mickey Jin (@patch1t)<\/p>\n<p>Assets<br \/>Available for: macOS Sequoia<br \/>Impact: A malicious app with root privileges may be able to modify the<br \/>contents of system files<br \/>Description: This issue was addressed by removing the vulnerable code.<br \/>CVE-2024-44260: Mickey Jin (@patch1t)<\/p>\n<p>Contacts<br \/>Available for: macOS Sequoia<br \/>Impact: An app may be able to access information about a user&#8217;s contacts<br \/>Description: A privacy issue was addressed with improved private data<br \/>redaction for log entries.<br \/>CVE-2024-44298: Kirin (@Pwnrin) and 7feilee<\/p>\n<p>CoreMedia Playback<br \/>Available for: macOS Sequoia<br \/>Impact: A malicious app may be able to access private information<br \/>Description: This issue was addressed with improved handling of<br \/>symlinks.<br \/>CVE-2024-44273: pattern-f (@pattern_F_), Hikerell of Loadshine Lab<\/p>\n<p>CoreServicesUIAgent<br \/>Available for: macOS Sequoia<br \/>Impact: An app may be able to modify protected parts of the file system<br \/>Description: This issue was addressed with additional entitlement<br \/>checks.<br \/>CVE-2024-44295: an anonymous researcher<\/p>\n<p>CoreText<br \/>Available for: macOS Sequoia<br \/>Impact: Processing a maliciously crafted font may result in the<br \/>disclosure of process memory<br \/>Description: The issue was addressed with improved checks.<br \/>CVE-2024-44240: Hossein Lotfi (@hosselot) of Trend Micro Zero Day<br \/>Initiative<br \/>CVE-2024-44302: Hossein Lotfi (@hosselot) of Trend Micro Zero Day<br \/>Initiative<\/p>\n<p>CUPS<br \/>Available for: macOS Sequoia<br \/>Impact: An attacker in a privileged network position may be able to leak<br \/>sensitive user information<br \/>Description: An issue existed in the parsing of URLs. This issue was<br \/>addressed with improved input validation.<br \/>CVE-2024-44213: Alexandre Bedard<\/p>\n<p>Find My<br \/>Available for: macOS Sequoia<br \/>Impact: An app may be able to read sensitive location information<br \/>Description: A privacy issue was addressed with improved private data<br \/>redaction for log entries.<br \/>CVE-2024-44289: Kirin (@Pwnrin)<\/p>\n<p>Foundation<br \/>Available for: macOS Sequoia<br \/>Impact: Parsing a file may lead to disclosure of user information<br \/>Description: An out-of-bounds read was addressed with improved input<br \/>validation.<br \/>CVE-2024-44282: Hossein Lotfi (@hosselot) of Trend Micro Zero Day<br \/>Initiative<\/p>\n<p>Game Controllers<br \/>Available for: macOS Sequoia<br \/>Impact: An attacker with physical access can input Game Controller<br \/>events to apps running on a locked device<br \/>Description: The issue was addressed by restricting options offered on a<br \/>locked device.<br \/>CVE-2024-44265: Ronny Stiftel<\/p>\n<p>ImageIO<br \/>Available for: macOS Sequoia<br \/>Impact: Processing an image may result in disclosure of process memory<br \/>Description: This issue was addressed with improved checks.<br \/>CVE-2024-44215: Junsung Lee working with Trend Micro Zero Day Initiative<\/p>\n<p>ImageIO<br \/>Available for: macOS Sequoia<br \/>Impact: Processing a maliciously crafted message may lead to a denial-<br \/>of-service<br \/>Description: The issue was addressed with improved bounds checks.<br \/>CVE-2024-44297: Jex Amro<\/p>\n<p>Installer<br \/>Available for: macOS Sequoia<br \/>Impact: An app may be able to access user-sensitive data<br \/>Description: An access issue was addressed with additional sandbox<br \/>restrictions.<br \/>CVE-2024-44216: Zhongquan Li (@Guluisacat)<\/p>\n<p>Installer<br \/>Available for: macOS Sequoia<br \/>Impact: A malicious application may be able to modify protected parts of<br \/>the file system<br \/>Description: The issue was addressed with improved checks.<br \/>CVE-2024-44287: Mickey Jin (@patch1t)<\/p>\n<p>IOGPUFamily<br \/>Available for: macOS Sequoia<br \/>Impact: A malicious app may be able to cause a denial-of-service<br \/>Description: The issue was addressed with improved memory handling.<br \/>CVE-2024-44197: Wang Yu of Cyberserval<\/p>\n<p>IOSurface<br \/>Available for: macOS Sequoia<br \/>Impact: An app may be able to cause unexpected system termination or<br \/>corrupt kernel memory<br \/>Description: A use-after-free issue was addressed with improved memory<br \/>management.<br \/>CVE-2024-44285: an anonymous researcher<\/p>\n<p>Kernel<br \/>Available for: macOS Sequoia<br \/>Impact: An app may be able to leak sensitive kernel state<br \/>Description: An information disclosure issue was addressed with improved<br \/>private data redaction for log entries.<br \/>CVE-2024-44239: Mateusz Krzywicki (@krzywix)<\/p>\n<p>Login Window<br \/>Available for: macOS Sequoia<br \/>Impact: A person with physical access to a Mac may be able to bypass<br \/>Login Window during a software update<br \/>Description: This issue was addressed through improved state management.<br \/>CVE-2024-44231: Toomas R\u00f6mer<\/p>\n<p>Login Window<br \/>Available for: macOS Sequoia<br \/>Impact: An attacker with physical access to a Mac may be able to view<br \/>protected content from the Login Window<br \/>Description: This issue was addressed through improved state management.<br \/>CVE-2024-44223: Jaime Bertran<\/p>\n<p>Maps<br \/>Available for: macOS Sequoia<br \/>Impact: An app may be able to read sensitive location information<br \/>Description: This issue was addressed with improved redaction of<br \/>sensitive information.<br \/>CVE-2024-44222: Kirin (@Pwnrin)<\/p>\n<p>Messages<br \/>Available for: macOS Sequoia<br \/>Impact: An app may be able to break out of its sandbox<br \/>Description: The issue was addressed with improved input sanitization.<br \/>CVE-2024-44256: Mickey Jin (@patch1t)<\/p>\n<p>Notification Center<br \/>Available for: macOS Sequoia<br \/>Impact: An app may be able to access sensitive user data<br \/>Description: A privacy issue was addressed with improved private data<br \/>redaction for log entries.<br \/>CVE-2024-44292: Kirin (@Pwnrin)<\/p>\n<p>Notification Center<br \/>Available for: macOS Sequoia<br \/>Impact: A user may be able to view sensitive user information<br \/>Description: A privacy issue was addressed with improved private data<br \/>redaction for log entries.<br \/>CVE-2024-44293: Kirin (@Pwnrin) and 7feilee<\/p>\n<p>PackageKit<br \/>Available for: macOS Sequoia<br \/>Impact: A malicious application may be able to modify protected parts of<br \/>the file system<br \/>Description: The issue was addressed with improved checks.<br \/>CVE-2024-44247: Un3xploitable of CW Research Inc<br \/>CVE-2024-44267: Bohdan Stasiuk (@Bohdan_Stasiuk), Un3xploitable of CW<br \/>Research Inc, Pedro T\u00f4rres (@t0rr3sp3dr0)<br \/>CVE-2024-44301: Bohdan Stasiuk (@Bohdan_Stasiuk), Un3xploitable of CW<br \/>Research Inc, Pedro T\u00f4rres (@t0rr3sp3dr0)<br \/>CVE-2024-44275: Arsenii Kostromin (0x3c3e)<\/p>\n<p>PackageKit<br \/>Available for: macOS Sequoia<br \/>Impact: An app may be able to bypass Privacy preferences<br \/>Description: A path deletion vulnerability was addressed by preventing<br \/>vulnerable code from running with privileges.<br \/>CVE-2024-44156: Arsenii Kostromin (0x3c3e)<br \/>CVE-2024-44159: Mickey Jin (@patch1t)<\/p>\n<p>PackageKit<br \/>Available for: macOS Sequoia<br \/>Impact: An app may be able to modify protected parts of the file system<br \/>Description: The issue was addressed with improved checks.<br \/>CVE-2024-44253: Mickey Jin (@patch1t), Csaba Fitzl (@theevilbit) of<br \/>Kandji<\/p>\n<p>PackageKit<br \/>Available for: macOS Sequoia<br \/>Impact: An attacker with root privileges may be able to delete protected<br \/>system files<br \/>Description: A path deletion vulnerability was addressed by preventing<br \/>vulnerable code from running with privileges.<br \/>CVE-2024-44294: Mickey Jin (@patch1t)<\/p>\n<p>PackageKit<br \/>Available for: macOS Sequoia<br \/>Impact: An app may be able to modify protected parts of the file system<br \/>Description: A permissions issue was addressed with additional<br \/>restrictions.<br \/>CVE-2024-44196: Csaba Fitzl (@theevilbit) of Kandji<\/p>\n<p>Photos<br \/>Available for: macOS Sequoia<br \/>Impact: An app may be able to access Contacts without user consent<br \/>Description: A permissions issue was addressed with additional<br \/>restrictions.<br \/>CVE-2024-40858: Csaba Fitzl (@theevilbit) of Kandji<\/p>\n<p>Pro Res<br \/>Available for: macOS Sequoia<br \/>Impact: An app may be able to cause unexpected system termination or<br \/>corrupt kernel memory<br \/>Description: The issue was addressed with improved memory handling.<br \/>CVE-2024-44277: an anonymous researcher and Yinyi Wu(@_3ndy1) from Dawn<br \/>Security Lab of JD.com, Inc.<\/p>\n<p>Quick Look<br \/>Available for: macOS Sequoia<br \/>Impact: An app may be able to read arbitrary files<br \/>Description: A logic issue was addressed with improved validation.<br \/>CVE-2024-44195: an anonymous researcher<\/p>\n<p>Safari Downloads<br \/>Available for: macOS Sequoia<br \/>Impact: An attacker may be able to misuse a trust relationship to<br \/>download malicious content<br \/>Description: This issue was addressed through improved state management.<br \/>CVE-2024-44259: Narendra Bhati, Manager of Cyber Security at Suma Soft<br \/>Pvt. Ltd, Pune (India)<\/p>\n<p>Safari Private Browsing<br \/>Available for: macOS Sequoia<br \/>Impact: Private browsing may leak some browsing history<br \/>Description: An information leakage was addressed with additional<br \/>validation.<br \/>CVE-2024-44229: Lucas Di Tomase<\/p>\n<p>Sandbox<br \/>Available for: macOS Sequoia<br \/>Impact: An app may be able to access user-sensitive data<br \/>Description: This issue was addressed with improved validation of<br \/>symlinks.<br \/>CVE-2024-44211: Gergely Kalman (@gergely_kalman) and Csaba Fitzl<br \/>(@theevilbit)<\/p>\n<p>SceneKit<br \/>Available for: macOS Sequoia<br \/>Impact: Processing a maliciously crafted file may lead to heap<br \/>corruption<br \/>Description: This issue was addressed with improved checks.<br \/>CVE-2024-44218: Michael DePlante (@izobashi) of Trend Micro Zero Day<br \/>Initiative<\/p>\n<p>Shortcuts<br \/>Available for: macOS Sequoia<br \/>Impact: An app may be able to access sensitive user data<br \/>Description: This issue was addressed with improved redaction of<br \/>sensitive information.<br \/>CVE-2024-44254: Kirin (@Pwnrin)<\/p>\n<p>Shortcuts<br \/>Available for: macOS Sequoia<br \/>Impact: A malicious app may use shortcuts to access restricted files<br \/>Description: A logic issue was addressed with improved checks.<br \/>CVE-2024-44269: an anonymous researcher<\/p>\n<p>sips<br \/>Available for: macOS Sequoia<br \/>Impact: Processing a maliciously crafted file may lead to unexpected app<br \/>termination<br \/>Description: An out-of-bounds access issue was addressed with improved<br \/>bounds checking.<br \/>CVE-2024-44236: Hossein Lotfi (@hosselot) of Trend Micro Zero Day<br \/>Initiative<br \/>CVE-2024-44237: Hossein Lotfi (@hosselot) of Trend Micro Zero Day<br \/>Initiative<\/p>\n<p>sips<br \/>Available for: macOS Sequoia<br \/>Impact: Parsing a file may lead to disclosure of user information<br \/>Description: An out-of-bounds read was addressed with improved input<br \/>validation.<br \/>CVE-2024-44279: Hossein Lotfi (@hosselot) of Trend Micro Zero Day<br \/>Initiative<br \/>CVE-2024-44281: Hossein Lotfi (@hosselot) of Trend Micro Zero Day<br \/>Initiative<\/p>\n<p>sips<br \/>Available for: macOS Sequoia<br \/>Impact: Parsing a maliciously crafted file may lead to an unexpected app<br \/>termination<br \/>Description: An out-of-bounds read was addressed with improved bounds<br \/>checking.<br \/>CVE-2024-44283: Hossein Lotfi (@hosselot) of Trend Micro Zero Day<br \/>Initiative<\/p>\n<p>sips<br \/>Available for: macOS Sequoia<br \/>Impact: Parsing a maliciously crafted file may lead to an unexpected app<br \/>termination<br \/>Description: An out-of-bounds write issue was addressed with improved<br \/>input validation.<br \/>CVE-2024-44284: Junsung Lee, dw0r! working with Trend Micro Zero Day<br \/>Initiative<\/p>\n<p>Siri<br \/>Available for: macOS Sequoia<br \/>Impact: An app may be able to access sensitive user data<br \/>Description: This issue was addressed with improved redaction of<br \/>sensitive information.<br \/>CVE-2024-44194: Rodolphe Brunetti (@eisw0lf)<\/p>\n<p>Siri<br \/>Available for: macOS Sequoia<br \/>Impact: A sandboxed app may be able to access sensitive user data in<br \/>system logs<br \/>Description: An information disclosure issue was addressed with improved<br \/>private data redaction for log entries.<br \/>CVE-2024-44278: Kirin (@Pwnrin)<\/p>\n<p>SystemMigration<br \/>Available for: macOS Sequoia<br \/>Impact: A malicious app may be able to create symlinks to protected<br \/>regions of the disk<br \/>Description: This issue was addressed with improved validation of<br \/>symlinks.<br \/>CVE-2024-44264: Mickey Jin (@patch1t)<\/p>\n<p>WebKit<br \/>Available for: macOS Sequoia<br \/>Impact: Processing maliciously crafted web content may prevent Content<br \/>Security Policy from being enforced<br \/>Description: The issue was addressed with improved checks.<br \/>WebKit Bugzilla: 278765<br \/>CVE-2024-44296: Narendra Bhati, Manager of Cyber Security at Suma Soft<br \/>Pvt. Ltd, Pune (India)<\/p>\n<p>WebKit<br \/>Available for: macOS Sequoia<br \/>Impact: Processing maliciously crafted web content may lead to an<br \/>unexpected process crash<br \/>Description: A memory corruption issue was addressed with improved input<br \/>validation.<br \/>WebKit Bugzilla: 279780<br \/>CVE-2024-44244: an anonymous researcher, Q1IQ (@q1iqF) and P1umer<br \/>(@p1umer)<\/p>\n<p>WindowServer<br \/>Available for: macOS Sequoia<br \/>Impact: An app may be able to access sensitive user data<br \/>Description: This issue was addressed with improved redaction of<br \/>sensitive information.<br \/>CVE-2024-44257: Bohdan Stasiuk (@Bohdan_Stasiuk)<\/p>\n<p>Additional recognition<\/p>\n<p>Airport<br \/>We would like to acknowledge Bohdan Stasiuk (@Bohdan_Stasiuk),<br \/>K\u5b9d(@Pwnrin) for their assistance.<\/p>\n<p>Calculator<br \/>We would like to acknowledge Kenneth Chew for their assistance.<\/p>\n<p>Calendar<br \/>We would like to acknowledge K\u5b9d(@Pwnrin) for their assistance.<\/p>\n<p>ImageIO<br \/>We would like to acknowledge Amir Bazine and Karsten K\u00f6nig of<br \/>CrowdStrike Counter Adversary Operations, an anonymous researcher for<br \/>their assistance.<\/p>\n<p>Messages<br \/>We would like to acknowledge Collin Potter, an anonymous researcher for<br \/>their assistance.<\/p>\n<p>NetworkExtension<br \/>We would like to acknowledge Patrick Wardle of DoubleYou &amp; the<br \/>Objective-See Foundation for their assistance.<\/p>\n<p>Notification Center<br \/>We would like to acknowledge Kirin (@Pwnrin) and LFYSec for their<br \/>assistance.<\/p>\n<p>Photos<br \/>We would like to acknowledge James Robertson for their assistance.<\/p>\n<p>Safari Private Browsing<br \/>We would like to acknowledge an anonymous researcher, r00tdaddy for<br \/>their assistance.<\/p>\n<p>Safari Tabs<br \/>We would like to acknowledge Jaydev Ahire for their assistance.<\/p>\n<p>Security<br \/>We would like to acknowledge Bing Shi, Wenchao Li and Xiaolong Bai of<br \/>Alibaba Group for their assistance.<\/p>\n<p>Siri<br \/>We would like to acknowledge Bistrit Dahal for their assistance.<\/p>\n<p>macOS Sequoia 15.1 may be obtained from the Mac App Store or Apple&#8217;s<br \/>Software Downloads web site: https:\/\/support.apple.com\/downloads\/<\/p>\n<p>All information is also posted on the Apple Security Releases<br \/>web site: https:\/\/support.apple.com\/100100.<\/p>\n<p>This message is signed with Apple&#8217;s Product Security PGP key,<br \/>and details are available at:<br \/>https:\/\/www.apple.com\/support\/security\/pgp\/<\/p>\n<p>&#8212;&#8211;BEGIN PGP SIGNATURE&#8212;&#8211;<\/p>\n<p>iQIzBAEBCAAdFiEEsz9altA7uTI+rE\/qX+5d1TXaIvoFAmcf\/5IACgkQX+5d1TXa<br \/>IvpDBw\/9FRph9Y6CcfUCPh6XQXhb25fsLE9L9qkW6gB2aF+\/NUC55OGNlHKoxmCU<br \/>WCY\/\/cOs164iB+ETsGqX3I3U6vD\/IqVwSfdpRpaNtdaEZnmFZPKLwJ4VzQufZV1a<br \/>N8XxyVaxpPFh\/8AmGdm0vqRv7x++brH8Z61Jt4AYdbg5Pph16zDBZxxLHUfTxY5a<br \/>j7GBdCVUwzSF6oSJZl2Mj9SoTfwVHqz2Xyp1x7w9IJKQaUQPfPghhPj15yJH5qTD<br \/>3jiyRdy18TfzXSFMiOGaq\/VbeQWIAEO6Vc7138n0T9vMwLsKx\/ag3\/wkia4LEWJ7<br \/>YIcKRpriM0bVYwgj14KDXItnWYCQn7DNH2ACqUto8bxC9NKxbhVIJJR4e8uz+UxL<br \/>zQ7RfAMjbwG1H6JoJsYh81gPAuvgEMYAmXo\/l5Kot8Gledzeal7yU6Jd6EQJegFg<br \/>boMJw5a5Gv9cui71llWqqLk3naxWpFF+1Cpw81PutRD2WwRVh4y3e4SMeL7f9pva<br \/>GOTigtDbuH6Trin\/wCZIlJ\/HHM0Y1fNzEXVLWLMziBpxhZNQMb02jYGYJOhzb10u<br \/>DZcVV\/7VfQPDbA2\/866L7N0KJH+9uitpO1ybf6sgbpvYLdEsgDE923c1vWnGW8O9<br \/>HtipeZ1KlK5EKr9vx3WIOHqznNIc38jdpAZ4xqhU0NjfbSUMbWs=<br \/>=csbI<br \/>&#8212;&#8211;END PGP SIGNATURE&#8212;&#8211;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>&#8212;&#8211;BEGIN PGP SIGNED MESSAGE&#8212;&#8211;Hash: SHA256 APPLE-SA-10-28-2024-3 macOS Sequoia 15.1 macOS Sequoia 15.1 addresses the following issues.Information about the security content is also available athttps:\/\/support.apple.com\/121564. Apple maintains a Security Releases page athttps:\/\/support.apple.com\/100100 which lists recentsoftware updates with security advisories. ApacheImpact: Multiple issues existed in ApacheDescription: This is a vulnerability in open source code and AppleSoftware is &hellip;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[26],"tags":[],"class_list":["post-59984","post","type-post","status-publish","format-standard","hentry","category-vulnerability"],"_links":{"self":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts\/59984","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/comments?post=59984"}],"version-history":[{"count":0,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts\/59984\/revisions"}],"wp:attachment":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/media?parent=59984"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/categories?post=59984"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/tags?post=59984"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}