HIGH🇵🇱 Wersja polska

CVE-2024-27808

CVSS 8.8v3.1pub. 2024-06-10upd. 2026-04-02

The issue was addressed with improved memory handling. This issue is fixed in Safari 17.5, iOS 17.5 and iPadOS 17.5, macOS Sonoma 14.5, tvOS 17.5, visionOS 1.2, watchOS 10.5. Processing web content may lead to arbitrary code execution.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
  • Apple iPadOS

    OS
    Apple
    < 17.5
  • Apple iOS

    OS
    Apple
    < 17.5
  • Apple macOS

    OS
    Apple
    14.0 – 14.5 (excl.)
  • Apple Safari

    APP
    Apple
    < 17.5
  • Apple tvOS

    OS
    Apple
    < 17.5
  • Apple Visionos

    OS
    Apple
    < 1.2
  • Apple watchOS

    OS
    Apple
    < 10.5
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
RCE
CWE
References

Related vulnerabilities

CVE-2026-65400CRITICAL9.8⚠ KEVPL ✓same product

Pominięcie uwierzytelniania w Screen Sharing na macOS

CVE-2025-10585CRITICAL9.8⚠ KEVPL ✓same product

Type confusion w V8 (Google Chrome) — zdalne uszkodzenie sterty

CVE-2025-43300CRITICAL10.0⚠ KEVPL ✓same product

Apple iOS/iPadOS/macOS — out-of-bounds write przy przetwarzaniu obrazu

CVE-2025-31200CRITICAL9.8⚠ KEVPL ✓same product

Apple — memory corruption (RCE) w przetwarzaniu strumieni audio

CVE-2025-31201CRITICAL9.8⚠ KEVPL ✓same product

Apple: Obejście Pointer Authentication w iOS, macOS i innych platformach