Skip to content
Appaloosa Scout

macOS

macOS 13.7.2

Official advisory

33 CVEs fixed by this release.

Release date
2024-12-11
End of support
2025-09-15 EOL
CVEs fixed
33
CISA KEV
0
Critical
0
High
1
NVD pending
32

CVEs fixed

CVE Severity
CVE-2024-45490

Microsoft Security Update Guide entry — NVD enrichira.

HIGH 9.8
CVE-2024-44201

[Apple libarchive] Processing a malicious crafted file may lead to a denial-of-service

N/A
CVE-2024-44224

[Apple StorageKit] A malicious app may be able to gain root privileges

N/A
CVE-2024-44225

[Apple libxpc] An app may be able to gain elevated privileges

N/A
CVE-2024-44248

[Apple Screen Sharing Server] A user with screen sharing access may be able to view another user's screen

N/A
CVE-2024-44291

[Apple Software Update] A malicious app may be able to gain root privileges

N/A
CVE-2024-44300

[Apple Crash Reporter] An app may be able to access protected user data

N/A
CVE-2024-45306

[Apple Vim] Processing a maliciously crafted file may lead to heap corruption

N/A
CVE-2024-54466

[Apple DiskArbitration] An encrypted volume may be accessed by a different user without prompting for the password

N/A
CVE-2024-54468

[Apple Kernel] An app may be able to break out of its sandbox

N/A
CVE-2024-54474

[Apple PackageKit] An app may be able to access user-sensitive data

N/A
CVE-2024-54475

[Apple System Settings] An app may be able to determine a user’s current location

N/A
CVE-2024-54476

[Apple PackageKit] An app may be able to access user-sensitive data

N/A
CVE-2024-54477

[Apple Apple Software Restore] An app may be able to access user-sensitive data

N/A
CVE-2024-54486

[Apple FontParser] Processing a maliciously crafted font may result in the disclosure of process memory

N/A
CVE-2024-54488

[Apple Accounts] Photos in the Hidden Photos Album may be viewed without authentication

N/A
CVE-2024-54489

[Apple Disk Utility] Running a mount command may unexpectedly execute arbitrary code

N/A
CVE-2024-54494

[Apple Kernel] An attacker may be able to create a read-only memory mapping that can be written to

N/A
CVE-2024-54498

[Apple SharedFileList] An app may be able to break out of its sandbox

N/A
CVE-2024-54500

[Apple ImageIO] Processing a maliciously crafted image may result in disclosure of process memory

N/A
CVE-2024-54501

[Apple SceneKit] Processing a maliciously crafted file may lead to a denial of service

N/A
CVE-2024-54510

[Apple Kernel] An app may be able to leak sensitive kernel state

N/A
CVE-2024-54514

[Apple libxpc] An app may be able to break out of its sandbox

N/A
CVE-2024-54520

[Apple System Settings] An app may be able to overwrite arbitrary files

N/A
CVE-2024-54526

[Apple AppleMobileFileIntegrity] A malicious app may be able to access private information

N/A
CVE-2024-54527

[Apple AppleMobileFileIntegrity] An app may be able to access sensitive user data

N/A
CVE-2024-54528

[Apple SharedFileList] An app may be able to overwrite arbitrary files

N/A
CVE-2024-54529

[Apple Audio] An app may be able to execute arbitrary code out of its sandbox or with certain elevated privileges

N/A
CVE-2024-54537

[Apple QuickTime Player] An app may be able to read and write files outside of its sandbox

N/A
CVE-2024-54539

[Apple WindowServer] An app may be able to capture keyboard events from the lock screen

N/A
CVE-2024-54541

[Apple APFS] An app may be able to access user-sensitive data

N/A
CVE-2024-54547

[Apple Dock] An app may be able to access protected user data

N/A
CVE-2024-54557

[Apple SharedFileList] An attacker may gain access to protected parts of the file system

N/A