CRITICAL🇵🇱 Wersja polska

CVE-2024-44241

CVSS 9.8v3.1pub. 2024-12-12upd. 2026-04-02

The issue was addressed with improved bounds checks. This issue is fixed in iOS 18.1 and iPadOS 18.1, macOS Sequoia 15.1. An attacker may be able to cause unexpected system termination or arbitrary code execution in DCP firmware.

🤖 AI Analysis
How it works

The problem resulted from improper bounds checking in DCP firmware. An attacker can provide specially crafted data that exceeds the acceptable ranges processed by the display coprocessor firmware. This can result in system instability or execution of arbitrary code at the DCP firmware level. Apple fixed the vulnerability by implementing improved bounds verification mechanisms.

Impact

An attacker can cause unexpected system termination (denial of service) or arbitrary code execution (RCE) in the context of DCP firmware on a vulnerable device.

Mitigation & patch

Devices must be urgently updated to iOS 18.1, iPadOS 18.1, or macOS Sequoia 15.1. Detailed information is available in Apple security bulletins at https://support.apple.com/en-us/121563 and https://support.apple.com/en-us/121564

Who is affected

Apple iOS in versions earlier than 18.1 and Apple iPadOS in versions earlier than 18.1; the vulnerability also affects macOS Sequoia in versions earlier than 15.1

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  • Apple iPadOS

    OS
    Apple
    < 18.1
  • Apple iOS

    OS
    Apple
    < 18.1
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
RCE
CWE
References

Related vulnerabilities

CVE-2025-43300CRITICAL10.0⚠ KEVPL ✓same product

Apple iOS/iPadOS/macOS — out-of-bounds write przy przetwarzaniu obrazu

CVE-2025-31200CRITICAL9.8⚠ KEVPL ✓same product

Apple — memory corruption (RCE) w przetwarzaniu strumieni audio

CVE-2025-31201CRITICAL9.8⚠ KEVPL ✓same product

Apple: Obejście Pointer Authentication w iOS, macOS i innych platformach

CVE-2025-24201CRITICAL10.0⚠ KEVPL ✓same product

Apple WebKit: out-of-bounds write umożliwiający ucieczkę z sandbox przeglądarki

CVE-2025-24085CRITICAL10.0⚠ KEVPL ✓same product

Use-after-free w Apple iOS/iPadOS/macOS — privilege escalation przez aplikację