macOS
macOS 15
Advisory officiel103 CVE corrigées par cette release.
- Date de sortie
- 2024-09-16
- Fin de support
- —
- CVE corrigées
- 103
- KEV CISA
- 0
- Critique
- 0
- Élevé
- 2
- En attente NVD
- 100
CVE corrigées
| CVE | Sévérité | KEV | Publié | Description |
|---|---|---|---|---|
|
CVE-2024-39894
Microsoft Security Update Guide entry — NVD enrichira. |
HIGH 7.5 | — | Microsoft Security Update Guide entry — NVD enrichira. | |
|
CVE-2023-4504
Microsoft Security Update Guide entry — NVD enrichira. |
HIGH 7.0 | — | Microsoft Security Update Guide entry — NVD enrichira. | |
|
CVE-2024-41957
Microsoft Security Update Guide entry — NVD enrichira. |
MEDIUM 5.3 | — | Microsoft Security Update Guide entry — NVD enrichira. | |
|
CVE-2024-44172
[Apple Contacts] An app may be able to access contacts |
N/A | — | [Apple Contacts] An app may be able to access contacts | |
|
CVE-2024-40855
[Apple DiskArbitration] A sandboxed app may be able to access sensitive user data |
N/A | — | [Apple DiskArbitration] A sandboxed app may be able to access sensitive user data | |
|
CVE-2024-44122
[Apple LaunchServices] An application may be able to break out of its sandbox |
N/A | — | [Apple LaunchServices] An application may be able to break out of its sandbox | |
|
CVE-2024-44126
[Apple ARKit] Processing a maliciously crafted file may lead to heap corruption |
N/A | — | [Apple ARKit] Processing a maliciously crafted file may lead to heap corruption | |
|
CVE-2024-44137
[Apple Screen Capture] An attacker with physical access may be able to share items from the lock screen |
N/A | — | [Apple Screen Capture] An attacker with physical access may be able to share items from the lock screen | |
|
CVE-2024-44144
[Apple SceneKit] Processing a maliciously crafted file may lead to unexpected app termination |
N/A | — | [Apple SceneKit] Processing a maliciously crafted file may lead to unexpected app termination | |
|
CVE-2024-44155
[Apple Safari] Maliciously crafted web content may violate iframe sandboxing policy |
N/A | — | [Apple Safari] Maliciously crafted web content may violate iframe sandboxing policy | |
|
CVE-2024-44175
[Apple Kernel] An app may be able to access sensitive user data |
N/A | — | [Apple Kernel] An app may be able to access sensitive user data | |
|
CVE-2023-5841
[Apple Model I/O] Processing a maliciously crafted image may lead to a denial-of-service |
N/A | — | [Apple Model I/O] Processing a maliciously crafted image may lead to a denial-of-service | |
|
CVE-2024-23237
[Apple Wi-Fi] An app may be able to cause a denial-of-service |
N/A | — | [Apple Wi-Fi] An app may be able to cause a denial-of-service | |
|
CVE-2024-27795
[Apple AppSandbox] A camera extension may be able to access the internet |
N/A | — | [Apple AppSandbox] A camera extension may be able to access the internet | |
|
CVE-2024-27849
[Apple Core Data] An app may be able to read sensitive location information |
N/A | — | [Apple Core Data] An app may be able to read sensitive location information | |
|
CVE-2024-27858
[Apple Music] An app may be able to access protected user data |
N/A | — | [Apple Music] An app may be able to access protected user data | |
|
CVE-2024-27860
[Apple AppleVA] An application may be able to read restricted memory |
N/A | — | [Apple AppleVA] An application may be able to read restricted memory | |
|
CVE-2024-27861
[Apple AppleVA] An application may be able to read restricted memory |
N/A | — | [Apple AppleVA] An application may be able to read restricted memory | |
|
CVE-2024-27869
[Apple Control Center] An app may be able to record the screen without an indicator |
N/A | — | [Apple Control Center] An app may be able to record the screen without an indicator | |
|
CVE-2024-27875
[Apple Control Center] Privacy Indicators for microphone or camera access may be attributed incorrectly |
N/A | — | [Apple Control Center] Privacy Indicators for microphone or camera access may be attributed incorrectly | |
|
CVE-2024-27876
[Apple Compression] Unpacking a maliciously crafted archive may allow an attacker to write arbitrary files |
N/A | — | [Apple Compression] Unpacking a maliciously crafted archive may allow an attacker to write arbitrary files | |
|
CVE-2024-27880
[Apple ImageIO] Processing a maliciously crafted file may lead to unexpected app termination |
N/A | — | [Apple ImageIO] Processing a maliciously crafted file may lead to unexpected app termination | |
|
CVE-2024-40770
[Apple Wi-Fi] A non-privileged user may be able to modify restricted network settings |
N/A | — | [Apple Wi-Fi] A non-privileged user may be able to modify restricted network settings | |
|
CVE-2024-40791
[Apple Mail Accounts] An app may be able to access information about a user's contacts |
N/A | — | [Apple Mail Accounts] An app may be able to access information about a user's contacts | |
|
CVE-2024-40792
[Apple Airport] A malicious app may be able to change network settings |
N/A | — | [Apple Airport] A malicious app may be able to change network settings | |
|
CVE-2024-40797
[Apple Safari] Visiting a malicious website may lead to user interface spoofing |
N/A | — | [Apple Safari] Visiting a malicious website may lead to user interface spoofing | |
|
CVE-2024-40801
[Apple Security Initialization] An app may be able to access protected user data |
N/A | — | [Apple Security Initialization] An app may be able to access protected user data | |
|
CVE-2024-40825
[Apple APFS] A malicious app with root privileges may be able to modify the contents of system files |
N/A | — | [Apple APFS] A malicious app with root privileges may be able to modify the contents of system files | |
|
CVE-2024-40826
[Apple Printing] An unencrypted document may be written to a temporary file when using print preview |
N/A | — | [Apple Printing] An unencrypted document may be written to a temporary file when using print preview | |
|
CVE-2024-40831
[Apple Image Capture] An app may be able to access a user's Photos Library |
N/A | — | [Apple Image Capture] An app may be able to access a user's Photos Library | |
|
CVE-2024-40837
[Apple AppleMobileFileIntegrity] An app may be able to access protected user data |
N/A | — | [Apple AppleMobileFileIntegrity] An app may be able to access protected user data | |
|
CVE-2024-40838
[Apple Notification Center] A malicious app may be able to access notifications from the user's device |
N/A | — | [Apple Notification Center] A malicious app may be able to access notifications from the user's device | |
|
CVE-2024-40841
[Apple AppleVA] Processing a maliciously crafted video file may lead to unexpected app termination |
N/A | — | [Apple AppleVA] Processing a maliciously crafted video file may lead to unexpected app termination | |
|
CVE-2024-40842
[Apple XProtect] An app may be able to access user-sensitive data |
N/A | — | [Apple XProtect] An app may be able to access user-sensitive data | |
|
CVE-2024-40843
[Apple XProtect] An app may be able to modify protected parts of the file system |
N/A | — | [Apple XProtect] An app may be able to modify protected parts of the file system | |
|
CVE-2024-40844
[Apple Shortcuts] An app may be able to observe data displayed to the user by Shortcuts |
N/A | — | [Apple Shortcuts] An app may be able to observe data displayed to the user by Shortcuts | |
|
CVE-2024-40845
[Apple AppleGraphicsControl] Processing a maliciously crafted video file may lead to unexpected app termination |
N/A | — | [Apple AppleGraphicsControl] Processing a maliciously crafted video file may lead to unexpected app termination | |
|
CVE-2024-40846
[Apple AppleGraphicsControl] Processing a maliciously crafted video file may lead to unexpected app termination |
N/A | — | [Apple AppleGraphicsControl] Processing a maliciously crafted video file may lead to unexpected app termination | |
|
CVE-2024-40847
[Apple AppleMobileFileIntegrity] An app may be able to access sensitive user data |
N/A | — | [Apple AppleMobileFileIntegrity] An app may be able to access sensitive user data | |
|
CVE-2024-40848
[Apple AppleMobileFileIntegrity] An attacker may be able to read sensitive information |
N/A | — | [Apple AppleMobileFileIntegrity] An attacker may be able to read sensitive information | |
|
CVE-2024-40850
[Apple Game Center] An app may be able to access user-sensitive data |
N/A | — | [Apple Game Center] An app may be able to access user-sensitive data | |
|
CVE-2024-40856
[Apple Wi-Fi] An attacker may be able to force a device to disconnect from a secure network |
N/A | — | [Apple Wi-Fi] An attacker may be able to force a device to disconnect from a secure network | |
|
CVE-2024-40857
[Apple WebKit] Processing maliciously crafted web content may lead to universal cross site scripting |
N/A | — | [Apple WebKit] Processing maliciously crafted web content may lead to universal cross site scripting | |
|
CVE-2024-40859
[Apple TV App] An app may be able to access user-sensitive data |
N/A | — | [Apple TV App] An app may be able to access user-sensitive data | |
|
CVE-2024-40860
[Apple sudo] An app may be able to modify protected parts of the file system |
N/A | — | [Apple sudo] An app may be able to modify protected parts of the file system | |
|
CVE-2024-40861
[Apple Installer] An app may be able to gain root privileges |
N/A | — | [Apple Installer] An app may be able to gain root privileges | |
|
CVE-2024-40866
[Apple WebKit] Visiting a malicious website may lead to address bar spoofing |
N/A | — | [Apple WebKit] Visiting a malicious website may lead to address bar spoofing | |
|
CVE-2024-44123
[Apple Security] A malicious app with root privileges may be able to access keyboard input and location information wit… |
N/A | — | [Apple Security] A malicious app with root privileges may be able to access keyboard input and location information without user consent | |
|
CVE-2024-44125
[Apple Sandbox] A malicious application may be able to leak sensitive user information |
N/A | — | [Apple Sandbox] A malicious application may be able to leak sensitive user information | |
|
CVE-2024-44128
[Apple Automator] An Automator Quick Action workflow may be able to bypass Gatekeeper |
N/A | — | [Apple Automator] An Automator Quick Action workflow may be able to bypass Gatekeeper | |
|
CVE-2024-44129
[Apple Accounts] An app may be able to leak sensitive user information |
N/A | — | [Apple Accounts] An app may be able to leak sensitive user information | |
|
CVE-2024-44130
[Apple APNs] An app with root privileges may be able to access private information |
N/A | — | [Apple APNs] An app with root privileges may be able to access private information | |
|
CVE-2024-44131
[Apple FileProvider] An app may be able to access sensitive user data |
N/A | — | [Apple FileProvider] An app may be able to access sensitive user data | |
|
CVE-2024-44132
[Apple ArchiveService] An app may be able to break out of its sandbox |
N/A | — | [Apple ArchiveService] An app may be able to break out of its sandbox | |
|
CVE-2024-44133
[Apple TCC] On MDM managed devices, an app may be able to bypass certain Privacy preferences |
N/A | — | [Apple TCC] On MDM managed devices, an app may be able to bypass certain Privacy preferences | |
|
CVE-2024-44134
[Apple Wi-Fi] An app may be able to read sensitive location information |
N/A | — | [Apple Wi-Fi] An app may be able to read sensitive location information | |
|
CVE-2024-44135
[Apple AppSandbox] An app may be able to access protected files within an App Sandbox container |
N/A | — | [Apple AppSandbox] An app may be able to access protected files within an App Sandbox container | |
|
CVE-2024-44145
[Apple Sidecar] An attacker with physical access to a macOS device with Sidecar enabled may be able to bypass the Lock … |
N/A | — | [Apple Sidecar] An attacker with physical access to a macOS device with Sidecar enabled may be able to bypass the Lock Screen | |
|
CVE-2024-44146
[Apple copyfile] An app may be able to break out of its sandbox |
N/A | — | [Apple copyfile] An app may be able to break out of its sandbox | |
|
CVE-2024-44148
[Apple Disk Images] An app may be able to break out of its sandbox |
N/A | — | [Apple Disk Images] An app may be able to break out of its sandbox | |
|
CVE-2024-44149
[Apple Quick Look] An app may be able to access protected user data |
N/A | — | [Apple Quick Look] An app may be able to access protected user data | |
|
CVE-2024-44151
[Apple bless] An app may be able to modify protected parts of the file system |
N/A | — | [Apple bless] An app may be able to modify protected parts of the file system | |
|
CVE-2024-44152
[Apple System Settings] An app may be able to access user-sensitive data |
N/A | — | [Apple System Settings] An app may be able to access user-sensitive data | |
|
CVE-2024-44153
[Apple Accounts] An app may be able to access user-sensitive data |
N/A | — | [Apple Accounts] An app may be able to access user-sensitive data | |
|
CVE-2024-44154
[Apple AppleGraphicsControl] Processing a maliciously crafted file may lead to unexpected app termination |
N/A | — | [Apple AppleGraphicsControl] Processing a maliciously crafted file may lead to unexpected app termination | |
|
CVE-2024-44158
[Apple Shortcuts] A shortcut may output sensitive user data without consent |
N/A | — | [Apple Shortcuts] A shortcut may output sensitive user data without consent | |
|
CVE-2024-44160
[Apple Intel Graphics Driver] Processing a maliciously crafted texture may lead to unexpected app termination |
N/A | — | [Apple Intel Graphics Driver] Processing a maliciously crafted texture may lead to unexpected app termination | |
|
CVE-2024-44161
[Apple Intel Graphics Driver] Processing a maliciously crafted texture may lead to unexpected app termination |
N/A | — | [Apple Intel Graphics Driver] Processing a maliciously crafted texture may lead to unexpected app termination | |
|
CVE-2024-44163
[Apple Sandbox] A malicious application may be able to access private information |
N/A | — | [Apple Sandbox] A malicious application may be able to access private information | |
|
CVE-2024-44164
[Apple AppleMobileFileIntegrity] An app may be able to bypass Privacy preferences |
N/A | — | [Apple AppleMobileFileIntegrity] An app may be able to bypass Privacy preferences | |
|
CVE-2024-44165
[Apple Kernel] Network traffic may leak outside a VPN tunnel |
N/A | — | [Apple Kernel] Network traffic may leak outside a VPN tunnel | |
|
CVE-2024-44166
[Apple System Settings] An app may be able to access user-sensitive data |
N/A | — | [Apple System Settings] An app may be able to access user-sensitive data | |
|
CVE-2024-44167
[Apple Notes] An app may be able to overwrite arbitrary files |
N/A | — | [Apple Notes] An app may be able to overwrite arbitrary files | |
|
CVE-2024-44168
[Apple AppleMobileFileIntegrity] An app may be able to modify protected parts of the file system |
N/A | — | [Apple AppleMobileFileIntegrity] An app may be able to modify protected parts of the file system | |
|
CVE-2024-44169
[Apple IOSurfaceAccelerator] An app may be able to cause unexpected system termination |
N/A | — | [Apple IOSurfaceAccelerator] An app may be able to cause unexpected system termination | |
|
CVE-2024-44170
[Apple Siri] An app may be able to access user-sensitive data |
N/A | — | [Apple Siri] An app may be able to access user-sensitive data | |
|
CVE-2024-44174
[Apple Screen Capture] An attacker may be able to view restricted content from the lock screen |
N/A | — | [Apple Screen Capture] An attacker may be able to view restricted content from the lock screen | |
|
CVE-2024-44176
[Apple ImageIO] Processing an image may lead to a denial-of-service |
N/A | — | [Apple ImageIO] Processing an image may lead to a denial-of-service | |
|
CVE-2024-44177
[Apple Dock] An app may be able to access user-sensitive data |
N/A | — | [Apple Dock] An app may be able to access user-sensitive data | |
|
CVE-2024-44178
[Apple PackageKit] An app may be able to modify protected parts of the file system |
N/A | — | [Apple PackageKit] An app may be able to modify protected parts of the file system | |
|
CVE-2024-44179
[Apple Siri] An attacker with physical access to a device may be able to read contact numbers from the lock screen |
N/A | — | [Apple Siri] An attacker with physical access to a device may be able to read contact numbers from the lock screen | |
|
CVE-2024-44181
[Apple Maps] An app may be able to read sensitive location information |
N/A | — | [Apple Maps] An app may be able to read sensitive location information | |
|
CVE-2024-44182
[Apple App Intents] An app may be able to access sensitive data logged when a shortcut fails to launch another app |
N/A | — | [Apple App Intents] An app may be able to access sensitive data logged when a shortcut fails to launch another app | |
|
CVE-2024-44183
[Apple mDNSResponder] An app may be able to cause a denial-of-service |
N/A | — | [Apple mDNSResponder] An app may be able to cause a denial-of-service | |
|
CVE-2024-44184
[Apple Transparency] An app may be able to access user-sensitive data |
N/A | — | [Apple Transparency] An app may be able to access user-sensitive data | |
|
CVE-2024-44186
[Apple NSColor] An app may be able to access protected user data |
N/A | — | [Apple NSColor] An app may be able to access protected user data | |
|
CVE-2024-44187
[Apple WebKit] A malicious website may exfiltrate data cross-origin |
N/A | — | [Apple WebKit] A malicious website may exfiltrate data cross-origin | |
|
CVE-2024-44188
[Apple Accounts] An app may be able to access protected user data |
N/A | — | [Apple Accounts] An app may be able to access protected user data | |
|
CVE-2024-44189
[Apple WindowServer] A logic issue existed where a process may be able to capture screen contents without user consent |
N/A | — | [Apple WindowServer] A logic issue existed where a process may be able to capture screen contents without user consent | |
|
CVE-2024-44190
[Apple System Settings] An app may be able to read arbitrary files |
N/A | — | [Apple System Settings] An app may be able to read arbitrary files | |
|
CVE-2024-44191
[Apple Kernel] An app may gain unauthorized access to Bluetooth |
N/A | — | [Apple Kernel] An app may gain unauthorized access to Bluetooth | |
|
CVE-2024-44192
[Apple WebKit] Processing maliciously crafted web content may lead to an unexpected process crash |
N/A | — | [Apple WebKit] Processing maliciously crafted web content may lead to an unexpected process crash | |
|
CVE-2024-44198
[Apple libxml2] Processing maliciously crafted web content may lead to an unexpected process crash |
N/A | — | [Apple libxml2] Processing maliciously crafted web content may lead to an unexpected process crash | |
|
CVE-2024-44203
[Apple Sandbox] An app may be able to access a user's Photos Library |
N/A | — | [Apple Sandbox] An app may be able to access a user's Photos Library | |
|
CVE-2024-44208
[Apple WindowServer] An app may be able to bypass certain Privacy preferences |
N/A | — | [Apple WindowServer] An app may be able to bypass certain Privacy preferences | |
|
CVE-2024-44227
[Apple Wi-Fi] An app may be able to cause unexpected system termination or corrupt kernel memory |
N/A | — | [Apple Wi-Fi] An app may be able to cause unexpected system termination or corrupt kernel memory | |
|
CVE-2024-54463
[Apple Image Capture] An app may be able to access removable volumes without user consent |
N/A | — | [Apple Image Capture] An app may be able to access removable volumes without user consent | |
|
CVE-2024-54467
[Apple WebKit] A malicious website may exfiltrate data cross-origin |
N/A | — | [Apple WebKit] A malicious website may exfiltrate data cross-origin | |
|
CVE-2024-54469
[Apple FileProvider] A local user may be able to leak sensitive user information |
N/A | — | [Apple FileProvider] A local user may be able to leak sensitive user information | |
|
CVE-2024-54473
[Apple Maps] An app may be able to access user-sensitive data |
N/A | — | [Apple Maps] An app may be able to access user-sensitive data | |
|
CVE-2024-54546
[Apple Wi-Fi] An app may be able to cause unexpected system termination or corrupt kernel memory |
N/A | — | [Apple Wi-Fi] An app may be able to cause unexpected system termination or corrupt kernel memory | |
|
CVE-2024-54558
[Apple TCC] An app may be able to trick a user into granting access to photos from the user's photo library |
N/A | — | [Apple TCC] An app may be able to trick a user into granting access to photos from the user's photo library | |
|
CVE-2024-54560
[Apple LaunchServices] A malicious app may be able to modify other apps without having App Management permission |
N/A | — | [Apple LaunchServices] A malicious app may be able to modify other apps without having App Management permission |