Skip to content
Appaloosa Scout

macOS

83 CVEs fixed by this release.

Release date
2024-12-11
End of support
CVEs fixed
83
CISA KEV
0
Critical
1
High
3
NVD pending
79

CVEs fixed

CVE Severity
CVE-2023-47100

[Apple Perl] Multiple issues in Perl

CRITICAL 9.8
CVE-2024-45490

Microsoft Security Update Guide entry — NVD enrichira.

HIGH 9.8
CVE-2023-31486

Microsoft Security Update Guide entry — NVD enrichira.

HIGH 8.1
CVE-2023-31484

CPAN.pm before 2.35 does not verify TLS certificates when downloading distributions over HTTPS.

HIGH 8.1
CVE-2024-40864

[Apple Apple Account] An attacker in a privileged network position may be able to track a user's activity

N/A
CVE-2024-54502

[Apple WebKit] Processing maliciously crafted web content may lead to an unexpected process crash

N/A
CVE-2024-54508

[Apple WebKit] Processing maliciously crafted web content may lead to an unexpected process crash

N/A
CVE-2024-54533

[Apple Spotlight] An app may be able to access sensitive user data

N/A
CVE-2024-54534

[Apple WebKit] Processing maliciously crafted web content may lead to memory corruption

N/A
CVE-2024-54543

[Apple WebKit] Processing maliciously crafted web content may lead to memory corruption

N/A
CVE-2024-44243

[Apple StorageKit] An app may be able to modify protected parts of the file system

N/A
CVE-2024-54478

[Apple ICU] Processing maliciously crafted web content may lead to an unexpected process crash

N/A
CVE-2024-54497

[Apple QuartzCore] Processing web content may lead to a denial-of-service

N/A
CVE-2024-54509

[Apple ASP TCP] An app may be able to cause unexpected system termination or write kernel memory

N/A
CVE-2016-1246

[Apple Perl] Multiple issues in Perl

N/A
CVE-2023-32395

[Apple Perl] An app may be able to modify protected parts of the file system

N/A
CVE-2024-44220

[Apple AppleGraphicsControl] Parsing a maliciously crafted video file may lead to unexpected system termination

N/A
CVE-2024-44224

[Apple StorageKit] A malicious app may be able to gain root privileges

N/A
CVE-2024-44225

[Apple libxpc] An app may be able to gain elevated privileges

N/A
CVE-2024-44245

[Apple Kernel] An app may be able to cause unexpected system termination or corrupt kernel memory

N/A
CVE-2024-44246

[Apple Safari] On a device with Private Relay enabled, adding a website to the Safari Reading List may reveal the origi…

N/A
CVE-2024-44271

[Apple Control Center] An app may be able to record the screen without an indicator

N/A
CVE-2024-44291

[Apple Software Update] A malicious app may be able to gain root privileges

N/A
CVE-2024-44300

[Apple Crash Reporter] An app may be able to access protected user data

N/A
CVE-2024-45306

[Apple Vim] Processing a maliciously crafted file may lead to heap corruption

N/A
CVE-2024-54465

[Apple LaunchServices] An app may be able to elevate privileges

N/A
CVE-2024-54466

[Apple DiskArbitration] An encrypted volume may be accessed by a different user without prompting for the password

N/A
CVE-2024-54468

[Apple Kernel] An app may be able to break out of its sandbox

N/A
CVE-2024-54474

[Apple PackageKit] An app may be able to access user-sensitive data

N/A
CVE-2024-54475

[Apple System Settings] An app may be able to determine a user’s current location

N/A
CVE-2024-54476

[Apple PackageKit] An app may be able to access user-sensitive data

N/A
CVE-2024-54477

[Apple Apple Software Restore] An app may be able to access user-sensitive data

N/A
CVE-2024-54479

[Apple WebKit] Processing maliciously crafted web content may lead to an unexpected process crash

N/A
CVE-2024-54484

[Apple MediaRemote] An app may be able to access user-sensitive data

N/A
CVE-2024-54485

[Apple VoiceOver] An attacker with physical access to an iOS device may be able to view notification content from the l…

N/A
CVE-2024-54486

[Apple FontParser] Processing a maliciously crafted font may result in the disclosure of process memory

N/A
CVE-2024-54488

[Apple Accounts] Photos in the Hidden Photos Album may be viewed without authentication

N/A
CVE-2024-54489

[Apple Disk Utility] Running a mount command may unexpectedly execute arbitrary code

N/A
CVE-2024-54490

[Apple AppleMobileFileIntegrity] A local attacker may gain access to user's Keychain items

N/A
CVE-2024-54491

[Apple Logging] A malicious application may be able to determine a user's current location

N/A
CVE-2024-54492

[Apple Passwords] An attacker in a privileged network position may be able to alter network traffic

N/A
CVE-2024-54493

[Apple Shortcuts] Privacy indicators for microphone access may be attributed incorrectly

N/A
CVE-2024-54494

[Apple Kernel] An attacker may be able to create a read-only memory mapping that can be written to

N/A
CVE-2024-54495

[Apple Swift] An app may be able to modify protected parts of the file system

N/A
CVE-2024-54498

[Apple SharedFileList] An app may be able to break out of its sandbox

N/A
CVE-2024-54499

[Apple ImageIO] Processing a maliciously crafted image may lead to arbitrary code execution

N/A
CVE-2024-54500

[Apple ImageIO] Processing a maliciously crafted image may result in disclosure of process memory

N/A
CVE-2024-54501

[Apple SceneKit] Processing a maliciously crafted file may lead to a denial of service

N/A
CVE-2024-54504

[Apple Notification Center] An app may be able to access user-sensitive data

N/A
CVE-2024-54505

[Apple WebKit] Processing maliciously crafted web content may lead to memory corruption

N/A
CVE-2024-54506

[Apple IOMobileFrameBuffer] An attacker may be able to cause unexpected system termination or arbitrary code execution …

N/A
CVE-2024-54507

[Apple Kernel] An attacker with user privileges may be able to read kernel memory

N/A
CVE-2024-54510

[Apple Kernel] An app may be able to leak sensitive kernel state

N/A
CVE-2024-54513

[Apple Crash Reporter] An app may be able to access sensitive user data

N/A
CVE-2024-54514

[Apple libxpc] An app may be able to break out of its sandbox

N/A
CVE-2024-54515

[Apple SharedFileList] A malicious app may be able to gain root privileges

N/A
CVE-2024-54516

[Apple SharedFileList] An app may be able to approve a launch daemon without user consent

N/A
CVE-2024-54517

[Apple IOMobileFrameBuffer] An app may be able to corrupt coprocessor memory

N/A
CVE-2024-54518

[Apple IOMobileFrameBuffer] An app may be able to corrupt coprocessor memory

N/A
CVE-2024-54519

[Apple Find My] An app may be able to read sensitive location information

N/A
CVE-2024-54520

[Apple System Settings] An app may be able to overwrite arbitrary files

N/A
CVE-2024-54522

[Apple IOMobileFrameBuffer] An app may be able to corrupt coprocessor memory

N/A
CVE-2024-54523

[Apple IOMobileFrameBuffer] An app may be able to corrupt coprocessor memory

N/A
CVE-2024-54524

[Apple SharedFileList] A malicious app may be able to access arbitrary files

N/A
CVE-2024-54525

[Apple MobileBackup] Restoring a maliciously crafted backup file may lead to modification of protected system files

N/A
CVE-2024-54526

[Apple AppleMobileFileIntegrity] A malicious app may be able to access private information

N/A
CVE-2024-54527

[Apple AppleMobileFileIntegrity] An app may be able to access sensitive user data

N/A
CVE-2024-54528

[Apple SharedFileList] An app may be able to overwrite arbitrary files

N/A
CVE-2024-54529

[Apple Audio] An app may be able to execute arbitrary code out of its sandbox or with certain elevated privileges

N/A
CVE-2024-54530

[Apple Passkeys] Password autofill may fill in passwords after failing authentication

N/A
CVE-2024-54531

[Apple Kernel] An app may be able to bypass kASLR

N/A
CVE-2024-54536

[Apple MobileAccessoryUpdater] An app may be able to edit NVRAM variables

N/A
CVE-2024-54537

[Apple QuickTime Player] An app may be able to read and write files outside of its sandbox

N/A
CVE-2024-54539

[Apple WindowServer] An app may be able to capture keyboard events from the lock screen

N/A
CVE-2024-54541

[Apple APFS] An app may be able to access user-sensitive data

N/A
CVE-2024-54542

[Apple Safari Private Browsing] Private Browsing tabs may be accessed without authentication

N/A
CVE-2024-54547

[Apple Dock] An app may be able to access protected user data

N/A
CVE-2024-54549

[Apple Sync Services] An app may be able to access user-sensitive data

N/A
CVE-2024-54550

[Apple Contacts] An app may be able to view autocompleted contact information from Messages and Mail in system logs

N/A
CVE-2024-54557

[Apple SharedFileList] An attacker may gain access to protected parts of the file system

N/A
CVE-2024-54559

[Apple Sandbox] An app may be able to access sensitive user data

N/A
CVE-2024-54565

[Apple XProtect] An app may be able to access sensitive user data

N/A
CVE-2024-54568

[Apple ATS] Parsing a maliciously crafted file may lead to an unexpected app termination

N/A