iOS
iOS 18.2
Official advisory41 CVEs fixed by this release.
- Release date
- 2024-12-11
- End of support
- —
- CVEs fixed
- 41
- CISA KEV
- 0
- Critical
- 0
- High
- 1
- NVD pending
- 40
CVEs fixed
| CVE | Severity | KEV | Published | Description |
|---|---|---|---|---|
|
CVE-2024-45490
Microsoft Security Update Guide entry — NVD enrichira. |
HIGH 9.8 | — | Microsoft Security Update Guide entry — NVD enrichira. | |
|
CVE-2024-40864
[Apple Apple Account] An attacker in a privileged network position may be able to track a user's activity |
N/A | — | [Apple Apple Account] An attacker in a privileged network position may be able to track a user's activity | |
|
CVE-2024-54502
[Apple WebKit] Processing maliciously crafted web content may lead to an unexpected process crash |
N/A | — | [Apple WebKit] Processing maliciously crafted web content may lead to an unexpected process crash | |
|
CVE-2024-54508
[Apple WebKit] Processing maliciously crafted web content may lead to an unexpected process crash |
N/A | — | [Apple WebKit] Processing maliciously crafted web content may lead to an unexpected process crash | |
|
CVE-2024-54534
[Apple WebKit] Processing maliciously crafted web content may lead to memory corruption |
N/A | — | [Apple WebKit] Processing maliciously crafted web content may lead to memory corruption | |
|
CVE-2024-54543
[Apple WebKit] Processing maliciously crafted web content may lead to memory corruption |
N/A | — | [Apple WebKit] Processing maliciously crafted web content may lead to memory corruption | |
|
CVE-2024-54478
[Apple ICU] Processing maliciously crafted web content may lead to an unexpected process crash |
N/A | — | [Apple ICU] Processing maliciously crafted web content may lead to an unexpected process crash | |
|
CVE-2024-54497
[Apple QuartzCore] Processing web content may lead to a denial-of-service |
N/A | — | [Apple QuartzCore] Processing web content may lead to a denial-of-service | |
|
CVE-2024-44225
[Apple libxpc] An app may be able to gain elevated privileges |
N/A | — | [Apple libxpc] An app may be able to gain elevated privileges | |
|
CVE-2024-44245
[Apple Kernel] An app may be able to cause unexpected system termination or corrupt kernel memory |
N/A | — | [Apple Kernel] An app may be able to cause unexpected system termination or corrupt kernel memory | |
|
CVE-2024-44246
[Apple Safari] On a device with Private Relay enabled, adding a website to the Safari Reading List may reveal the origi… |
N/A | — | [Apple Safari] On a device with Private Relay enabled, adding a website to the Safari Reading List may reveal the originating IP address to the website | |
|
CVE-2024-44276
[Apple Passwords] A user in a privileged network position may be able to leak sensitive information |
N/A | — | [Apple Passwords] A user in a privileged network position may be able to leak sensitive information | |
|
CVE-2024-45306
[Apple Vim] Processing a maliciously crafted file may lead to heap corruption |
N/A | — | [Apple Vim] Processing a maliciously crafted file may lead to heap corruption | |
|
CVE-2024-54468
[Apple Kernel] An app may be able to break out of its sandbox |
N/A | — | [Apple Kernel] An app may be able to break out of its sandbox | |
|
CVE-2024-54479
[Apple WebKit] Processing maliciously crafted web content may lead to an unexpected process crash |
N/A | — | [Apple WebKit] Processing maliciously crafted web content may lead to an unexpected process crash | |
|
CVE-2024-54485
[Apple VoiceOver] An attacker with physical access to an iOS device may be able to view notification content from the l… |
N/A | — | [Apple VoiceOver] An attacker with physical access to an iOS device may be able to view notification content from the lock screen | |
|
CVE-2024-54486
[Apple FontParser] Processing a maliciously crafted font may result in the disclosure of process memory |
N/A | — | [Apple FontParser] Processing a maliciously crafted font may result in the disclosure of process memory | |
|
CVE-2024-54488
[Apple Accounts] Photos in the Hidden Photos Album may be viewed without authentication |
N/A | — | [Apple Accounts] Photos in the Hidden Photos Album may be viewed without authentication | |
|
CVE-2024-54492
[Apple Passwords] An attacker in a privileged network position may be able to alter network traffic |
N/A | — | [Apple Passwords] An attacker in a privileged network position may be able to alter network traffic | |
|
CVE-2024-54494
[Apple Kernel] An attacker may be able to create a read-only memory mapping that can be written to |
N/A | — | [Apple Kernel] An attacker may be able to create a read-only memory mapping that can be written to | |
|
CVE-2024-54499
[Apple ImageIO] Processing a maliciously crafted image may lead to arbitrary code execution |
N/A | — | [Apple ImageIO] Processing a maliciously crafted image may lead to arbitrary code execution | |
|
CVE-2024-54500
[Apple ImageIO] Processing a maliciously crafted image may result in disclosure of process memory |
N/A | — | [Apple ImageIO] Processing a maliciously crafted image may result in disclosure of process memory | |
|
CVE-2024-54501
[Apple SceneKit] Processing a maliciously crafted file may lead to a denial of service |
N/A | — | [Apple SceneKit] Processing a maliciously crafted file may lead to a denial of service | |
|
CVE-2024-54503
[Apple Audio] Muting a call while ringing may not result in mute being enabled |
N/A | — | [Apple Audio] Muting a call while ringing may not result in mute being enabled | |
|
CVE-2024-54505
[Apple WebKit] Processing maliciously crafted web content may lead to memory corruption |
N/A | — | [Apple WebKit] Processing maliciously crafted web content may lead to memory corruption | |
|
CVE-2024-54507
[Apple Kernel] An attacker with user privileges may be able to read kernel memory |
N/A | — | [Apple Kernel] An attacker with user privileges may be able to read kernel memory | |
|
CVE-2024-54510
[Apple Kernel] An app may be able to leak sensitive kernel state |
N/A | — | [Apple Kernel] An app may be able to leak sensitive kernel state | |
|
CVE-2024-54512
[Apple Face Gallery] A system binary could be used to fingerprint a user's Apple Account |
N/A | — | [Apple Face Gallery] A system binary could be used to fingerprint a user's Apple Account | |
|
CVE-2024-54513
[Apple Crash Reporter] An app may be able to access sensitive user data |
N/A | — | [Apple Crash Reporter] An app may be able to access sensitive user data | |
|
CVE-2024-54514
[Apple libxpc] An app may be able to break out of its sandbox |
N/A | — | [Apple libxpc] An app may be able to break out of its sandbox | |
|
CVE-2024-54517
[Apple IOMobileFrameBuffer] An app may be able to corrupt coprocessor memory |
N/A | — | [Apple IOMobileFrameBuffer] An app may be able to corrupt coprocessor memory | |
|
CVE-2024-54518
[Apple IOMobileFrameBuffer] An app may be able to corrupt coprocessor memory |
N/A | — | [Apple IOMobileFrameBuffer] An app may be able to corrupt coprocessor memory | |
|
CVE-2024-54522
[Apple IOMobileFrameBuffer] An app may be able to corrupt coprocessor memory |
N/A | — | [Apple IOMobileFrameBuffer] An app may be able to corrupt coprocessor memory | |
|
CVE-2024-54523
[Apple IOMobileFrameBuffer] An app may be able to corrupt coprocessor memory |
N/A | — | [Apple IOMobileFrameBuffer] An app may be able to corrupt coprocessor memory | |
|
CVE-2024-54525
[Apple MobileBackup] Restoring a maliciously crafted backup file may lead to modification of protected system files |
N/A | — | [Apple MobileBackup] Restoring a maliciously crafted backup file may lead to modification of protected system files | |
|
CVE-2024-54526
[Apple AppleMobileFileIntegrity] A malicious app may be able to access private information |
N/A | — | [Apple AppleMobileFileIntegrity] A malicious app may be able to access private information | |
|
CVE-2024-54527
[Apple AppleMobileFileIntegrity] An app may be able to access sensitive user data |
N/A | — | [Apple AppleMobileFileIntegrity] An app may be able to access sensitive user data | |
|
CVE-2024-54530
[Apple Passkeys] Password autofill may fill in passwords after failing authentication |
N/A | — | [Apple Passkeys] Password autofill may fill in passwords after failing authentication | |
|
CVE-2024-54541
[Apple APFS] An app may be able to access user-sensitive data |
N/A | — | [Apple APFS] An app may be able to access user-sensitive data | |
|
CVE-2024-54542
[Apple Safari Private Browsing] Private Browsing tabs may be accessed without authentication |
N/A | — | [Apple Safari Private Browsing] Private Browsing tabs may be accessed without authentication | |
|
CVE-2024-54550
[Apple Contacts] An app may be able to view autocompleted contact information from Messages and Mail in system logs |
N/A | — | [Apple Contacts] An app may be able to view autocompleted contact information from Messages and Mail in system logs |