Annual recap
Mobile security · 2024
2024 review indexed by Appaloosa Scout: 1,757 mobile CVE published, 39 added to the CISA KEV catalog (exploited in real attacks), 3 mobile apps affected by at least one KEV.
- CVE indexed this year
- 1,757
- CISA KEV added
- 39
- Tracked apps affected
- 3
Severity distribution
CRITICAL
86
HIGH
1,213
MEDIUM
399
LOW
59
Top 10 mobile KEV of the year
Sorted by number of mobile apps affected (CVSS as tiebreaker).
| CVE | Severity | Apps | Added to KEV | Description |
|---|---|---|---|---|
|
CVE-2024-39891
2 apps
|
MEDIUM 5.3 | 2 | 2024-07-23 | In the Twilio Authy API, accessed by Authy Android before 25.1.0 and Authy iOS before 26.1.0, an unauthenticated endpoint provided access t… |
|
CVE-2024-9680
1 apps
|
CRITICAL 9.8 | 1 | 2024-10-15 | An attacker was able to achieve code execution in the content process by exploiting a use-after-free in Animation timelines. We have had re… |
|
CVE-2024-4577
0 apps
|
CRITICAL 9.8 | 0 | 2024-06-12 | Argument Injection in PHP-CGI |
|
CVE-2024-21410
0 apps
|
CRITICAL 9.8 | 0 | 2024-02-15 | Microsoft Exchange Server Elevation of Privilege Vulnerability |
|
CVE-2023-29357
0 apps
|
CRITICAL 9.8 | 0 | 2024-01-10 | Microsoft SharePoint Server Elevation of Privilege Vulnerability |
|
CVE-2024-7971
0 apps
|
CRITICAL 9.6 | 0 | 2024-08-26 | Type confusion in V8 in Google Chrome prior to 128.0.6613.84 allowed a remote attacker to exploit heap corruption via a crafted HTML page. … |
|
CVE-2024-5274
0 apps
|
CRITICAL 9.6 | 0 | 2024-05-28 | Type Confusion in V8 in Google Chrome prior to 125.0.6422.112 allowed a remote attacker to execute arbitrary code inside a sandbox via a cr… |
|
CVE-2024-4947
0 apps
|
CRITICAL 9.6 | 0 | 2024-05-20 | Type Confusion in V8 in Google Chrome prior to 125.0.6422.60 allowed a remote attacker to execute arbitrary code inside a sandbox via a cra… |
|
CVE-2024-4671
0 apps
|
CRITICAL 9.6 | 0 | 2024-05-13 | Use after free in Visuals in Google Chrome prior to 124.0.6367.201 allowed a remote attacker who had compromised the renderer process to po… |
|
CVE-2024-44308
0 apps
|
HIGH 8.8 | 0 | 2024-11-21 | The issue was addressed with improved checks. This issue is fixed in Safari 18.1.1, iOS 17.7.2 and iPadOS 17.7.2, iOS 18.1.1 and iPadOS 18.… |
Top vendors by KEV this year
- 1 Authy 1 KEV · 1 apps
- 2 Mozilla 1 KEV · 1 apps
Most affected apps
Methodology
KEV: added to the CISA catalog during the year (kev_added_date). CVE: NVD publication date. Apps: those indexed in Scout at query time; the history evolves as new mappings are added.