Skip to content
Appaloosa Scout

iPadOS

40 CVEs fixed by this release.

Release date
2024-07-29
End of support
2025-09-15 EOL
CVEs fixed
40
CISA KEV
0
Critical
0
High
1
NVD pending
38

CVEs fixed

CVE Severity
CVE-2023-52356

[Apple ImageIO] Processing an image may lead to a denial-of-service

HIGH 7.5
CVE-2023-6277

Microsoft Security Update Guide entry — NVD enrichira.

MEDIUM 6.5
CVE-2024-27863

[Apple Kernel] A local attacker may be able to determine kernel memory layout

N/A
CVE-2024-27871

[Apple Sandbox] An app may be able to access protected user data

N/A
CVE-2024-27873

[Apple CoreMedia] Processing a maliciously crafted video file may lead to unexpected app termination

N/A
CVE-2024-40774

[Apple AppleMobileFileIntegrity] An app may be able to bypass Privacy preferences

N/A
CVE-2024-40776

[Apple WebKit] Processing maliciously crafted web content may lead to an unexpected process crash

N/A
CVE-2024-40777

[Apple ImageIO] Processing a maliciously crafted file may lead to unexpected app termination

N/A
CVE-2024-40778

[Apple Photos Storage] Photos in the Hidden Photos Album may be viewed without authentication

N/A
CVE-2024-40779

[Apple WebKit] Processing maliciously crafted web content may lead to an unexpected process crash

N/A
CVE-2024-40780

[Apple WebKit] Processing maliciously crafted web content may lead to an unexpected process crash

N/A
CVE-2024-40782

[Apple WebKit] Processing maliciously crafted web content may lead to an unexpected process crash

N/A
CVE-2024-40784

[Apple ImageIO] Processing a maliciously crafted file may lead to unexpected app termination

N/A
CVE-2024-40785

[Apple WebKit] Processing maliciously crafted web content may lead to a cross site scripting attack

N/A
CVE-2024-40786

[Apple Siri] An attacker may be able to view sensitive user information

N/A
CVE-2024-40787

[Apple Shortcuts] A shortcut may be able to bypass Internet permission requirements

N/A
CVE-2024-40788

[Apple Kernel] A local attacker may be able to cause unexpected system shutdown

N/A
CVE-2024-40789

[Apple WebKit] Processing maliciously crafted web content may lead to an unexpected process crash

N/A
CVE-2024-40793

[Apple Shortcuts] An app may be able to access user-sensitive data

N/A
CVE-2024-40794

[Apple WebKit] Private Browsing tabs may be accessed without authentication

N/A
CVE-2024-40795

[Apple Family Sharing] An app may be able to read sensitive location information

N/A
CVE-2024-40799

[Apple CoreGraphics] Processing a maliciously crafted file may lead to unexpected app termination

N/A
CVE-2024-40805

[Apple libxpc] An app may be able to bypass Privacy preferences

N/A
CVE-2024-40806

[Apple ImageIO] Processing a maliciously crafted file may lead to unexpected app termination

N/A
CVE-2024-40809

[Apple Shortcuts] A shortcut may be able to bypass Internet permission requirements

N/A
CVE-2024-40812

[Apple Shortcuts] A shortcut may be able to bypass Internet permission requirements

N/A
CVE-2024-40813

[Apple Phone] An attacker with physical access may be able to use Siri to access sensitive user data

N/A
CVE-2024-40815

[Apple dyld] A malicious attacker with arbitrary read and write capability may be able to bypass Pointer Authentication

N/A
CVE-2024-40818

[Apple Siri] An attacker with physical access may be able to use Siri to access sensitive user data

N/A
CVE-2024-40822

[Apple Siri] An attacker with physical access to a device may be able to access contacts from the lock screen

N/A
CVE-2024-40824

[Apple Sandbox] An app may be able to bypass Privacy preferences

N/A
CVE-2024-40829

[Apple VoiceOver] A user may be able to view restricted content from the lock screen

N/A
CVE-2024-40835

[Apple Shortcuts] A shortcut may be able to use sensitive data with certain actions without prompting the user

N/A
CVE-2024-40836

[Apple Shortcuts] A shortcut may be able to use sensitive data with certain actions without prompting the user

N/A
CVE-2024-44185

[Apple WebKit] Processing maliciously crafted web content may lead to an unexpected process crash

N/A
CVE-2024-44205

[Apple Siri] A sandboxed app may be able to access sensitive user data in system logs

N/A
CVE-2024-44206

[Apple WebKit] A user may be able to bypass some web content restrictions

N/A
CVE-2024-54551

[Apple WebKit] Processing web content may lead to a denial-of-service

N/A
CVE-2024-54564

[Apple AirDrop] A file received from AirDrop may not have the quarantine flag applied

N/A
CVE-2024-4558

Chromium: CVE-2024-4558 Use after free in ANGLE

N/A