iPadOS
iPadOS 18
Advisory officieliPadOS 18, publié le 2024-09-16, corrige 48 CVE. Les versions antérieures restent exposées à ces vulnérabilités.
- Date de sortie
- 2024-09-16
- Fin de support
- —
- CVE corrigées
- 48
- KEV CISA
- 0
2 critique · 7 élevé
CVE corrigées
| CVE |
|---|
|
CVE-2024-44217
CRITICAL 9.1
A permissions issue was addressed by removing vulnerable code and adding additional checks. This issue is fixed in iOS 18 and iPadOS 18. Password autofill may … |
|
CVE-2023-5841
CRITICAL 9.1
Due to a failure in validating the number of scanline samples of a OpenEXR file containing deep scanline data, Academy Software Foundation OpenEX image parsing… |
|
CVE-2024-44122
HIGH 8.8
A logic issue was addressed with improved checks. This issue is fixed in iOS 18 and iPadOS 18, macOS Sequoia 15, macOS Sonoma 14.7.1, macOS Ventura 13.7.1. An … |
|
CVE-2024-44126
HIGH 7.8
The issue was addressed with improved checks. This issue is fixed in iOS 17.7 and iPadOS 17.7, iOS 18 and iPadOS 18, macOS Sequoia 15, macOS Sonoma 14.7, macOS… |
|
CVE-2024-44227
HIGH 7.5
The issue was addressed with improved memory handling. This issue is fixed in iOS 18 and iPadOS 18, macOS Sequoia 15. An app may be able to cause unexpected sy… |
|
CVE-2024-44165
HIGH 7.5
A logic issue was addressed with improved checks. This issue is fixed in iOS 17.7 and iPadOS 17.7, iOS 18 and iPadOS 18, macOS Sequoia 15, macOS Sonoma 14.7, m… |
|
CVE-2024-40856
HIGH 7.5
An integrity issue was addressed with Beacon Protection. This issue is fixed in iOS 18 and iPadOS 18, macOS Sequoia 15, tvOS 18. An attacker may be able to for… |
|
CVE-2024-27879
HIGH 7.5
The issue was addressed with improved bounds checks. This issue is fixed in iOS 17.7 and iPadOS 17.7, iOS 18 and iPadOS 18. An attacker may be able to cause un… |
|
CVE-2024-27874
HIGH 7.5
This issue was addressed through improved state management. This issue is fixed in iOS 18 and iPadOS 18. A remote attacker may be able to cause a denial-of-ser… |
|
CVE-2024-54467
MEDIUM 6.5
A cookie management issue was addressed with improved state management. This issue is fixed in Safari 18, iOS 18 and iPadOS 18, macOS Sequoia 15, tvOS 18, visi… |
|
CVE-2024-44155
MEDIUM 6.5
A custom URL scheme handling issue was addressed with improved input validation. This issue is fixed in Safari 18, iOS 17.7.1 and iPadOS 17.7.1, iOS 18 and iPa… |
|
CVE-2024-44187
MEDIUM 6.5
A cross-origin issue existed with "iframe" elements. This was addressed with improved tracking of security origins. This issue is fixed in Safari 18, iOS 18 an… |
|
CVE-2024-44124
MEDIUM 6.5
This issue was addressed through improved state management. This issue is fixed in iOS 18 and iPadOS 18. A malicious Bluetooth input device may bypass pairing. |
|
CVE-2024-44145
MEDIUM 6.1
This issue was addressed through improved state management. This issue is fixed in iOS 18 and iPadOS 18, macOS Sequoia 15. An attacker with physical access to … |
|
CVE-2024-40857
MEDIUM 6.1
This issue was addressed through improved state management. This issue is fixed in Safari 18, iOS 18 and iPadOS 18, macOS Sequoia 15, tvOS 18, visionOS 2, watc… |
|
CVE-2024-40826
MEDIUM 6.1
A privacy issue was addressed with improved handling of files. This issue is fixed in iOS 18 and iPadOS 18, macOS Sequoia 15. An unencrypted document may be wr… |
|
CVE-2024-44192
MEDIUM 5.5
The issue was addressed with improved checks. This issue is fixed in Safari 18, iOS 18 and iPadOS 18, macOS Sequoia 15, tvOS 18, visionOS 2, watchOS 11. Proces… |
|
CVE-2024-54469
MEDIUM 5.5
The issue was addressed with improved checks. This issue is fixed in iOS 18 and iPadOS 18, macOS Sequoia 15, macOS Sonoma 14.7, macOS Ventura 13.7, visionOS 2.… |
|
CVE-2024-54560
MEDIUM 5.5
A logic issue was addressed with improved checks. This issue is fixed in iOS 18 and iPadOS 18, macOS Sequoia 15, tvOS 18, watchOS 11. A malicious app may be ab… |
|
CVE-2024-44144
MEDIUM 5.5
A buffer overflow was addressed with improved size validation. This issue is fixed in iOS 17.7.1 and iPadOS 17.7.1, iOS 18 and iPadOS 18, macOS Sequoia 15, mac… |
|
CVE-2024-44191
MEDIUM 5.5
This issue was addressed through improved state management. This issue is fixed in Xcode 16, iOS 17.7 and iPadOS 17.7, iOS 18 and iPadOS 18, macOS Sequoia 15, … |
|
CVE-2024-44198
MEDIUM 5.5
An integer overflow was addressed through improved input validation. This issue is fixed in iOS 18 and iPadOS 18, macOS Sequoia 15, tvOS 18, visionOS 2, watchO… |
|
CVE-2024-44167
MEDIUM 5.5
This issue was addressed by removing the vulnerable code. This issue is fixed in iOS 18 and iPadOS 18, macOS Sequoia 15, macOS Sonoma 14.7, macOS Ventura 13.7,… |
|
CVE-2024-44169
MEDIUM 5.5
The issue was addressed with improved memory handling. This issue is fixed in iOS 17.7 and iPadOS 17.7, iOS 18 and iPadOS 18, macOS Sequoia 15, macOS Sonoma 14… |
|
CVE-2024-44170
MEDIUM 5.5
A privacy issue was addressed by moving sensitive data to a more secure location. This issue is fixed in iOS 18 and iPadOS 18, macOS Sequoia 15, watchOS 11. An… |
|
CVE-2024-44176
MEDIUM 5.5
An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in iOS 17.7 and iPadOS 17.7, iOS 18 and iPadOS 18, macOS Sequoia… |
|
CVE-2024-44183
MEDIUM 5.5
A logic error was addressed with improved error handling. This issue is fixed in iOS 17.7 and iPadOS 17.7, iOS 18 and iPadOS 18, macOS Sequoia 15, macOS Sonoma… |
|
CVE-2024-44184
MEDIUM 5.5
A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 17.7 and iPadOS 17.7, iOS 18 and iPadOS 18, macOS Sequoia 15, macOS … |
|
CVE-2024-44131
MEDIUM 5.5
This issue was addressed with improved validation of symlinks. This issue is fixed in iOS 18 and iPadOS 18, macOS Sequoia 15. An app may be able to access sens… |
|
CVE-2024-44147
MEDIUM 5.5
This issue was addressed through improved state management. This issue is fixed in iOS 18 and iPadOS 18. An app may gain unauthorized access to Local Network. |
|
CVE-2024-40850
MEDIUM 5.5
A file access issue was addressed with improved input validation. This issue is fixed in iOS 17.7 and iPadOS 17.7, iOS 18 and iPadOS 18, macOS Sequoia 15, macO… |
|
CVE-2024-40863
MEDIUM 5.5
This issue was addressed with improved data protection. This issue is fixed in iOS 18 and iPadOS 18. An app may be able to leak sensitive user information. |
|
CVE-2024-27876
MEDIUM 5.5
A race condition was addressed with improved locking. This issue is fixed in iOS 17.7 and iPadOS 17.7, iOS 18 and iPadOS 18, macOS Sequoia 15, macOS Sonoma 14.… |
|
CVE-2024-27880
MEDIUM 5.5
An out-of-bounds read issue was addressed with improved input validation. This issue is fixed in iOS 17.7 and iPadOS 17.7, iOS 18 and iPadOS 18, macOS Sequoia … |
|
CVE-2024-27869
MEDIUM 5.5
The issue was addressed with improved checks. This issue is fixed in iOS 18 and iPadOS 18, macOS Sequoia 15. An app may be able to record the screen without an… |
|
CVE-2024-44202
MEDIUM 5.3
An authentication issue was addressed with improved state management. This issue is fixed in Safari 18, iOS 18 and iPadOS 18. Private Browsing tabs may be acce… |
|
CVE-2024-40852
MEDIUM 5.3
This issue was addressed by restricting options offered on a locked device. This issue is fixed in iOS 18 and iPadOS 18. An attacker may be able to see recent … |
|
CVE-2024-44127
MEDIUM 5.3
This issue was addressed through improved state management. This issue is fixed in iOS 17.7 and iPadOS 17.7, iOS 18 and iPadOS 18. Private Browsing tabs may be… |
|
CVE-2024-44171
MEDIUM 4.6
This issue was addressed through improved state management. This issue is fixed in iOS 17.7 and iPadOS 17.7, iOS 18 and iPadOS 18, watchOS 11. An attacker with… |
|
CVE-2024-40840
MEDIUM 4.6
This issue was addressed through improved state management. This issue is fixed in iOS 18 and iPadOS 18. An attacker with physical access may be able to use Si… |
|
CVE-2024-40853
LOW 3.3
This issue was addressed by restricting options offered on a locked device. This issue is fixed in iOS 18 and iPadOS 18. An attacker may be able to use Siri to… |
|
CVE-2024-40791
LOW 3.3
A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in iOS 17.7 and iPadOS 17.7, iOS 18 and iPadOS 18, macO… |
|
CVE-2024-40830
LOW 3.3
This issue was addressed with improved data protection. This issue is fixed in iOS 18 and iPadOS 18. An app may be able to enumerate a user's installed apps. |
|
CVE-2024-54558
LOW 2.8
A clickjacking issue was addressed with improved out-of-process view handling. This issue is fixed in iOS 18 and iPadOS 18, macOS Sequoia 15. An app may be abl… |
|
CVE-2024-44179
LOW 2.4
This issue was addressed by restricting options offered on a locked device. This issue is fixed in iOS 17.7 and iPadOS 17.7, iOS 18 and iPadOS 18, macOS Sequoi… |
|
CVE-2024-44180
LOW 2.4
The issue was addressed with improved checks. This issue is fixed in iOS 18 and iPadOS 18. An attacker with physical access may be able to access contacts from… |
|
CVE-2024-44139
LOW 2.4
The issue was addressed with improved checks. This issue is fixed in iOS 18 and iPadOS 18. An attacker with physical access may be able to access contacts from… |
|
CVE-2024-44123
LOW 2.3
A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 18 and iPadOS 18, macOS Sequoia 15. A malicious app with root privil… |
Piloter cette mise à jour iOS sur votre flotte
Appaloosa orchestre les mises à jour iOS et l'inventaire des apps de votre parc.