MEDIUM🇵🇱 Wersja polska

CVE-2024-27840

CVSS 6.3v3.1pub. 2024-06-10upd. 2026-04-02

The issue was addressed with improved memory handling. This issue is fixed in iOS 16.7.8 and iPadOS 16.7.8, iOS 17.5 and iPadOS 17.5, macOS Monterey 12.7.5, macOS Ventura 13.6.7, tvOS 17.5, visionOS 1.2, watchOS 10.5. An attacker that has already achieved kernel code execution may be able to bypass kernel memory protections.

CVSS Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:N/I:H/A:N
  • Apple iPadOS

    OS
    Apple
    < 16.7.817.0 – 17.5 (excl.)
  • Apple iOS

    OS
    Apple
    < 16.7.817.0 – 17.5 (excl.)
  • Apple macOS

    OS
    Apple
    12.0 – 12.7.5 (excl.)13.0 – 13.6.7 (excl.)
  • Apple tvOS

    OS
    Apple
    < 17.5
  • Apple Visionos

    OS
    Apple
    < 1.2
  • Apple watchOS

    OS
    Apple
    < 10.5
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
RCE
CWE
References

Related vulnerabilities

CVE-2026-65400CRITICAL9.8⚠ KEVPL ✓same product

Pominięcie uwierzytelniania w Screen Sharing na macOS

CVE-2025-10585CRITICAL9.8⚠ KEVPL ✓same product

Type confusion w V8 (Google Chrome) — zdalne uszkodzenie sterty

CVE-2025-43300CRITICAL10.0⚠ KEVPL ✓same product

Apple iOS/iPadOS/macOS — out-of-bounds write przy przetwarzaniu obrazu

CVE-2025-31200CRITICAL9.8⚠ KEVPL ✓same product

Apple — memory corruption (RCE) w przetwarzaniu strumieni audio

CVE-2025-31201CRITICAL9.8⚠ KEVPL ✓same product

Apple: Obejście Pointer Authentication w iOS, macOS i innych platformach