macOS
macOS 15.2
Official advisory83 CVEs fixed by this release.
- Release date
- 2024-12-11
- End of support
- —
- CVEs fixed
- 83
- CISA KEV
- 0
- Critical
- 1
- High
- 3
- NVD pending
- 79
CVEs fixed
| CVE | Severity | KEV | Published | Description |
|---|---|---|---|---|
|
CVE-2023-47100
[Apple Perl] Multiple issues in Perl |
CRITICAL 9.8 | — | [Apple Perl] Multiple issues in Perl | |
|
CVE-2024-45490
Microsoft Security Update Guide entry — NVD enrichira. |
HIGH 9.8 | — | Microsoft Security Update Guide entry — NVD enrichira. | |
|
CVE-2023-31486
Microsoft Security Update Guide entry — NVD enrichira. |
HIGH 8.1 | — | Microsoft Security Update Guide entry — NVD enrichira. | |
|
CVE-2023-31484
CPAN.pm before 2.35 does not verify TLS certificates when downloading distributions over HTTPS. |
HIGH 8.1 | — | CPAN.pm before 2.35 does not verify TLS certificates when downloading distributions over HTTPS. | |
|
CVE-2024-40864
[Apple Apple Account] An attacker in a privileged network position may be able to track a user's activity |
N/A | — | [Apple Apple Account] An attacker in a privileged network position may be able to track a user's activity | |
|
CVE-2024-54502
[Apple WebKit] Processing maliciously crafted web content may lead to an unexpected process crash |
N/A | — | [Apple WebKit] Processing maliciously crafted web content may lead to an unexpected process crash | |
|
CVE-2024-54508
[Apple WebKit] Processing maliciously crafted web content may lead to an unexpected process crash |
N/A | — | [Apple WebKit] Processing maliciously crafted web content may lead to an unexpected process crash | |
|
CVE-2024-54533
[Apple Spotlight] An app may be able to access sensitive user data |
N/A | — | [Apple Spotlight] An app may be able to access sensitive user data | |
|
CVE-2024-54534
[Apple WebKit] Processing maliciously crafted web content may lead to memory corruption |
N/A | — | [Apple WebKit] Processing maliciously crafted web content may lead to memory corruption | |
|
CVE-2024-54543
[Apple WebKit] Processing maliciously crafted web content may lead to memory corruption |
N/A | — | [Apple WebKit] Processing maliciously crafted web content may lead to memory corruption | |
|
CVE-2024-44243
[Apple StorageKit] An app may be able to modify protected parts of the file system |
N/A | — | [Apple StorageKit] An app may be able to modify protected parts of the file system | |
|
CVE-2024-54478
[Apple ICU] Processing maliciously crafted web content may lead to an unexpected process crash |
N/A | — | [Apple ICU] Processing maliciously crafted web content may lead to an unexpected process crash | |
|
CVE-2024-54497
[Apple QuartzCore] Processing web content may lead to a denial-of-service |
N/A | — | [Apple QuartzCore] Processing web content may lead to a denial-of-service | |
|
CVE-2024-54509
[Apple ASP TCP] An app may be able to cause unexpected system termination or write kernel memory |
N/A | — | [Apple ASP TCP] An app may be able to cause unexpected system termination or write kernel memory | |
|
CVE-2016-1246
[Apple Perl] Multiple issues in Perl |
N/A | — | [Apple Perl] Multiple issues in Perl | |
|
CVE-2023-32395
[Apple Perl] An app may be able to modify protected parts of the file system |
N/A | — | [Apple Perl] An app may be able to modify protected parts of the file system | |
|
CVE-2024-44220
[Apple AppleGraphicsControl] Parsing a maliciously crafted video file may lead to unexpected system termination |
N/A | — | [Apple AppleGraphicsControl] Parsing a maliciously crafted video file may lead to unexpected system termination | |
|
CVE-2024-44224
[Apple StorageKit] A malicious app may be able to gain root privileges |
N/A | — | [Apple StorageKit] A malicious app may be able to gain root privileges | |
|
CVE-2024-44225
[Apple libxpc] An app may be able to gain elevated privileges |
N/A | — | [Apple libxpc] An app may be able to gain elevated privileges | |
|
CVE-2024-44245
[Apple Kernel] An app may be able to cause unexpected system termination or corrupt kernel memory |
N/A | — | [Apple Kernel] An app may be able to cause unexpected system termination or corrupt kernel memory | |
|
CVE-2024-44246
[Apple Safari] On a device with Private Relay enabled, adding a website to the Safari Reading List may reveal the origi… |
N/A | — | [Apple Safari] On a device with Private Relay enabled, adding a website to the Safari Reading List may reveal the originating IP address to the website | |
|
CVE-2024-44271
[Apple Control Center] An app may be able to record the screen without an indicator |
N/A | — | [Apple Control Center] An app may be able to record the screen without an indicator | |
|
CVE-2024-44291
[Apple Software Update] A malicious app may be able to gain root privileges |
N/A | — | [Apple Software Update] A malicious app may be able to gain root privileges | |
|
CVE-2024-44300
[Apple Crash Reporter] An app may be able to access protected user data |
N/A | — | [Apple Crash Reporter] An app may be able to access protected user data | |
|
CVE-2024-45306
[Apple Vim] Processing a maliciously crafted file may lead to heap corruption |
N/A | — | [Apple Vim] Processing a maliciously crafted file may lead to heap corruption | |
|
CVE-2024-54465
[Apple LaunchServices] An app may be able to elevate privileges |
N/A | — | [Apple LaunchServices] An app may be able to elevate privileges | |
|
CVE-2024-54466
[Apple DiskArbitration] An encrypted volume may be accessed by a different user without prompting for the password |
N/A | — | [Apple DiskArbitration] An encrypted volume may be accessed by a different user without prompting for the password | |
|
CVE-2024-54468
[Apple Kernel] An app may be able to break out of its sandbox |
N/A | — | [Apple Kernel] An app may be able to break out of its sandbox | |
|
CVE-2024-54474
[Apple PackageKit] An app may be able to access user-sensitive data |
N/A | — | [Apple PackageKit] An app may be able to access user-sensitive data | |
|
CVE-2024-54475
[Apple System Settings] An app may be able to determine a user’s current location |
N/A | — | [Apple System Settings] An app may be able to determine a user’s current location | |
|
CVE-2024-54476
[Apple PackageKit] An app may be able to access user-sensitive data |
N/A | — | [Apple PackageKit] An app may be able to access user-sensitive data | |
|
CVE-2024-54477
[Apple Apple Software Restore] An app may be able to access user-sensitive data |
N/A | — | [Apple Apple Software Restore] An app may be able to access user-sensitive data | |
|
CVE-2024-54479
[Apple WebKit] Processing maliciously crafted web content may lead to an unexpected process crash |
N/A | — | [Apple WebKit] Processing maliciously crafted web content may lead to an unexpected process crash | |
|
CVE-2024-54484
[Apple MediaRemote] An app may be able to access user-sensitive data |
N/A | — | [Apple MediaRemote] An app may be able to access user-sensitive data | |
|
CVE-2024-54485
[Apple VoiceOver] An attacker with physical access to an iOS device may be able to view notification content from the l… |
N/A | — | [Apple VoiceOver] An attacker with physical access to an iOS device may be able to view notification content from the lock screen | |
|
CVE-2024-54486
[Apple FontParser] Processing a maliciously crafted font may result in the disclosure of process memory |
N/A | — | [Apple FontParser] Processing a maliciously crafted font may result in the disclosure of process memory | |
|
CVE-2024-54488
[Apple Accounts] Photos in the Hidden Photos Album may be viewed without authentication |
N/A | — | [Apple Accounts] Photos in the Hidden Photos Album may be viewed without authentication | |
|
CVE-2024-54489
[Apple Disk Utility] Running a mount command may unexpectedly execute arbitrary code |
N/A | — | [Apple Disk Utility] Running a mount command may unexpectedly execute arbitrary code | |
|
CVE-2024-54490
[Apple AppleMobileFileIntegrity] A local attacker may gain access to user's Keychain items |
N/A | — | [Apple AppleMobileFileIntegrity] A local attacker may gain access to user's Keychain items | |
|
CVE-2024-54491
[Apple Logging] A malicious application may be able to determine a user's current location |
N/A | — | [Apple Logging] A malicious application may be able to determine a user's current location | |
|
CVE-2024-54492
[Apple Passwords] An attacker in a privileged network position may be able to alter network traffic |
N/A | — | [Apple Passwords] An attacker in a privileged network position may be able to alter network traffic | |
|
CVE-2024-54493
[Apple Shortcuts] Privacy indicators for microphone access may be attributed incorrectly |
N/A | — | [Apple Shortcuts] Privacy indicators for microphone access may be attributed incorrectly | |
|
CVE-2024-54494
[Apple Kernel] An attacker may be able to create a read-only memory mapping that can be written to |
N/A | — | [Apple Kernel] An attacker may be able to create a read-only memory mapping that can be written to | |
|
CVE-2024-54495
[Apple Swift] An app may be able to modify protected parts of the file system |
N/A | — | [Apple Swift] An app may be able to modify protected parts of the file system | |
|
CVE-2024-54498
[Apple SharedFileList] An app may be able to break out of its sandbox |
N/A | — | [Apple SharedFileList] An app may be able to break out of its sandbox | |
|
CVE-2024-54499
[Apple ImageIO] Processing a maliciously crafted image may lead to arbitrary code execution |
N/A | — | [Apple ImageIO] Processing a maliciously crafted image may lead to arbitrary code execution | |
|
CVE-2024-54500
[Apple ImageIO] Processing a maliciously crafted image may result in disclosure of process memory |
N/A | — | [Apple ImageIO] Processing a maliciously crafted image may result in disclosure of process memory | |
|
CVE-2024-54501
[Apple SceneKit] Processing a maliciously crafted file may lead to a denial of service |
N/A | — | [Apple SceneKit] Processing a maliciously crafted file may lead to a denial of service | |
|
CVE-2024-54504
[Apple Notification Center] An app may be able to access user-sensitive data |
N/A | — | [Apple Notification Center] An app may be able to access user-sensitive data | |
|
CVE-2024-54505
[Apple WebKit] Processing maliciously crafted web content may lead to memory corruption |
N/A | — | [Apple WebKit] Processing maliciously crafted web content may lead to memory corruption | |
|
CVE-2024-54506
[Apple IOMobileFrameBuffer] An attacker may be able to cause unexpected system termination or arbitrary code execution … |
N/A | — | [Apple IOMobileFrameBuffer] An attacker may be able to cause unexpected system termination or arbitrary code execution in DCP firmware | |
|
CVE-2024-54507
[Apple Kernel] An attacker with user privileges may be able to read kernel memory |
N/A | — | [Apple Kernel] An attacker with user privileges may be able to read kernel memory | |
|
CVE-2024-54510
[Apple Kernel] An app may be able to leak sensitive kernel state |
N/A | — | [Apple Kernel] An app may be able to leak sensitive kernel state | |
|
CVE-2024-54513
[Apple Crash Reporter] An app may be able to access sensitive user data |
N/A | — | [Apple Crash Reporter] An app may be able to access sensitive user data | |
|
CVE-2024-54514
[Apple libxpc] An app may be able to break out of its sandbox |
N/A | — | [Apple libxpc] An app may be able to break out of its sandbox | |
|
CVE-2024-54515
[Apple SharedFileList] A malicious app may be able to gain root privileges |
N/A | — | [Apple SharedFileList] A malicious app may be able to gain root privileges | |
|
CVE-2024-54516
[Apple SharedFileList] An app may be able to approve a launch daemon without user consent |
N/A | — | [Apple SharedFileList] An app may be able to approve a launch daemon without user consent | |
|
CVE-2024-54517
[Apple IOMobileFrameBuffer] An app may be able to corrupt coprocessor memory |
N/A | — | [Apple IOMobileFrameBuffer] An app may be able to corrupt coprocessor memory | |
|
CVE-2024-54518
[Apple IOMobileFrameBuffer] An app may be able to corrupt coprocessor memory |
N/A | — | [Apple IOMobileFrameBuffer] An app may be able to corrupt coprocessor memory | |
|
CVE-2024-54519
[Apple Find My] An app may be able to read sensitive location information |
N/A | — | [Apple Find My] An app may be able to read sensitive location information | |
|
CVE-2024-54520
[Apple System Settings] An app may be able to overwrite arbitrary files |
N/A | — | [Apple System Settings] An app may be able to overwrite arbitrary files | |
|
CVE-2024-54522
[Apple IOMobileFrameBuffer] An app may be able to corrupt coprocessor memory |
N/A | — | [Apple IOMobileFrameBuffer] An app may be able to corrupt coprocessor memory | |
|
CVE-2024-54523
[Apple IOMobileFrameBuffer] An app may be able to corrupt coprocessor memory |
N/A | — | [Apple IOMobileFrameBuffer] An app may be able to corrupt coprocessor memory | |
|
CVE-2024-54524
[Apple SharedFileList] A malicious app may be able to access arbitrary files |
N/A | — | [Apple SharedFileList] A malicious app may be able to access arbitrary files | |
|
CVE-2024-54525
[Apple MobileBackup] Restoring a maliciously crafted backup file may lead to modification of protected system files |
N/A | — | [Apple MobileBackup] Restoring a maliciously crafted backup file may lead to modification of protected system files | |
|
CVE-2024-54526
[Apple AppleMobileFileIntegrity] A malicious app may be able to access private information |
N/A | — | [Apple AppleMobileFileIntegrity] A malicious app may be able to access private information | |
|
CVE-2024-54527
[Apple AppleMobileFileIntegrity] An app may be able to access sensitive user data |
N/A | — | [Apple AppleMobileFileIntegrity] An app may be able to access sensitive user data | |
|
CVE-2024-54528
[Apple SharedFileList] An app may be able to overwrite arbitrary files |
N/A | — | [Apple SharedFileList] An app may be able to overwrite arbitrary files | |
|
CVE-2024-54529
[Apple Audio] An app may be able to execute arbitrary code out of its sandbox or with certain elevated privileges |
N/A | — | [Apple Audio] An app may be able to execute arbitrary code out of its sandbox or with certain elevated privileges | |
|
CVE-2024-54530
[Apple Passkeys] Password autofill may fill in passwords after failing authentication |
N/A | — | [Apple Passkeys] Password autofill may fill in passwords after failing authentication | |
|
CVE-2024-54531
[Apple Kernel] An app may be able to bypass kASLR |
N/A | — | [Apple Kernel] An app may be able to bypass kASLR | |
|
CVE-2024-54536
[Apple MobileAccessoryUpdater] An app may be able to edit NVRAM variables |
N/A | — | [Apple MobileAccessoryUpdater] An app may be able to edit NVRAM variables | |
|
CVE-2024-54537
[Apple QuickTime Player] An app may be able to read and write files outside of its sandbox |
N/A | — | [Apple QuickTime Player] An app may be able to read and write files outside of its sandbox | |
|
CVE-2024-54539
[Apple WindowServer] An app may be able to capture keyboard events from the lock screen |
N/A | — | [Apple WindowServer] An app may be able to capture keyboard events from the lock screen | |
|
CVE-2024-54541
[Apple APFS] An app may be able to access user-sensitive data |
N/A | — | [Apple APFS] An app may be able to access user-sensitive data | |
|
CVE-2024-54542
[Apple Safari Private Browsing] Private Browsing tabs may be accessed without authentication |
N/A | — | [Apple Safari Private Browsing] Private Browsing tabs may be accessed without authentication | |
|
CVE-2024-54547
[Apple Dock] An app may be able to access protected user data |
N/A | — | [Apple Dock] An app may be able to access protected user data | |
|
CVE-2024-54549
[Apple Sync Services] An app may be able to access user-sensitive data |
N/A | — | [Apple Sync Services] An app may be able to access user-sensitive data | |
|
CVE-2024-54550
[Apple Contacts] An app may be able to view autocompleted contact information from Messages and Mail in system logs |
N/A | — | [Apple Contacts] An app may be able to view autocompleted contact information from Messages and Mail in system logs | |
|
CVE-2024-54557
[Apple SharedFileList] An attacker may gain access to protected parts of the file system |
N/A | — | [Apple SharedFileList] An attacker may gain access to protected parts of the file system | |
|
CVE-2024-54559
[Apple Sandbox] An app may be able to access sensitive user data |
N/A | — | [Apple Sandbox] An app may be able to access sensitive user data | |
|
CVE-2024-54565
[Apple XProtect] An app may be able to access sensitive user data |
N/A | — | [Apple XProtect] An app may be able to access sensitive user data | |
|
CVE-2024-54568
[Apple ATS] Parsing a maliciously crafted file may lead to an unexpected app termination |
N/A | — | [Apple ATS] Parsing a maliciously crafted file may lead to an unexpected app termination |