CVE-2024-27856
published 2025-01-15CVE-2024-27856: The issue was addressed with improved checks. This issue is fixed in Safari 17.5, iOS 16.7.8 and iPadOS 16.7.8, iOS 17.5 and iPadOS 17.5, macOS Sonoma 14.5…
PriorityP342high7.8CVSS 3.1
AVLACLPRNUIRSUCHIHAH
EPSS
0.63%
46.0th percentile
The issue was addressed with improved checks. This issue is fixed in Safari 17.5, iOS 16.7.8 and iPadOS 16.7.8, iOS 17.5 and iPadOS 17.5, macOS Sonoma 14.5, tvOS 17.5, visionOS 1.2, watchOS 10.5. Processing a file may lead to unexpected app termination or arbitrary code execution.
Affected
20 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | ios_16.7.8_and_ipados | — | — |
| apple | ios_17.5_and_ipados | — | — |
| apple | ios_and_ipados | < 16.7.8 | 16.7.8 |
| apple | ios_and_ipados | < 17.5 | 17.5 |
| apple | ipados | < 16.7.8 | 16.7.8 |
| apple | ipados | >= 17.0 < 17.5 | 17.5 |
| apple | iphone_os | < 16.7.8 | 16.7.8 |
| apple | iphone_os | >= 17.0 < 17.5 | 17.5 |
| apple | macos | < 14.5 | 14.5 |
| apple | macos_sonoma | — | — |
| apple | safari | < 17.5 | 17.5 |
| apple | safari | — | — |
| apple | tvos | < 17.5 | 17.5 |
| apple | tvos | — | — |
| apple | visionos | < 1.2 | 1.2 |
| apple | visionos | — | — |
| apple | watchos | < 10.5 | 10.5 |
| apple | watchos | — | — |
| debian | webkit2gtk | < webkit2gtk 2.46.0-2~deb12u1 (bookworm) | webkit2gtk 2.46.0-2~deb12u1 (bookworm) |
| debian | wpewebkit | < webkit2gtk 2.46.0-2~deb12u1 (bookworm) | webkit2gtk 2.46.0-2~deb12u1 (bookworm) |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
webkitgtk: Processing a file may lead to unexpected app termination or arbitrary code execution
vendor_redhat·2025-01-15·CVSS 7.8
CVE-2024-27856 [HIGH] CWE-94 webkitgtk: Processing a file may lead to unexpected app termination or arbitrary code execution
webkitgtk: Processing a file may lead to unexpected app termination or arbitrary code execution
The issue was addressed with improved checks. This issue is fixed in Safari 17.5, iOS 16.7.8 and iPadOS 16.7.8, iOS 17.5 and iPadOS 17.5, macOS Sonoma 14.5, tvOS 17.5, visionOS 1.2, watchOS 10.5. Processing a file may lead to unexpected app termination or arbitrary code execution.
A flaw was found in WebKitGTK. Processing malicious web content can cause unexpected app termination or arbitrary code execution due to improper checks.
Statement: To exploit this flaw, an attacker needs to trick a user into processing or loading malicious web content.
Mitigation: Do not process or load untrusted web content with WebKitGTK.
In Red Hat Enterprise Linux 7, the following packages require WebKitGTK4: e
Apple
CVE-2024-27856: visionOS 1.2
vendor_apple·2024-06-10·CVSS 7.8
CVE-2024-27856 [HIGH] CVE-2024-27856: visionOS 1.2
Apple Security Update: About the security content of visionOS 1.2
Product: visionOS
Version: 1.2
CVE: CVE-2024-27856
Component: WebKit
Impact: Processing a file may lead to unexpected app termination or arbitrary code execution
Description: The issue was addressed with improved checks.
Apple
CVE-2024-27856: Safari 17.5
vendor_apple·2024-05-13·CVSS 7.8
CVE-2024-27856 [HIGH] CVE-2024-27856: Safari 17.5
Apple Security Update: About the security content of Safari 17.5
Product: Safari
Version: 17.5
CVE: CVE-2024-27856
Component: WebKit
Impact: Processing a file may lead to unexpected app termination or arbitrary code execution
Description: The issue was addressed with improved checks.
Apple
CVE-2024-27856: iOS 16.7.8 and iPadOS 16.7.8
vendor_apple·2024-05-13·CVSS 7.8
CVE-2024-27856 [HIGH] CVE-2024-27856: iOS 16.7.8 and iPadOS 16.7.8
Apple Security Update: About the security content of iOS 16.7.8 and iPadOS 16.7.8
Product: iOS 16.7.8 and iPadOS
Version: 16.7.8
CVE: CVE-2024-27856
Component: WebKit
Impact: Processing a file may lead to unexpected app termination or arbitrary code execution
Description: The issue was addressed with improved checks.
Apple
CVE-2024-27856: iOS 17.5 and iPadOS 17.5
vendor_apple·2024-05-13·CVSS 7.8
CVE-2024-27856 [HIGH] CVE-2024-27856: iOS 17.5 and iPadOS 17.5
Apple Security Update: About the security content of iOS 17.5 and iPadOS 17.5
Product: iOS 17.5 and iPadOS
Version: 17.5
CVE: CVE-2024-27856
Component: WebKit
Impact: Processing a file may lead to unexpected app termination or arbitrary code execution
Description: The issue was addressed with improved checks.
Apple
CVE-2024-27856: macOS Sonoma 14.5
vendor_apple·2024-05-13·CVSS 7.8
CVE-2024-27856 [HIGH] CVE-2024-27856: macOS Sonoma 14.5
Apple Security Update: About the security content of macOS Sonoma 14.5
Product: macOS Sonoma
Version: 14.5
CVE: CVE-2024-27856
Component: WebKit
Impact: Processing a file may lead to unexpected app termination or arbitrary code execution
Description: The issue was addressed with improved checks.
Apple
CVE-2024-27856: tvOS 17.5
vendor_apple·2024-05-13·CVSS 7.8
CVE-2024-27856 [HIGH] CVE-2024-27856: tvOS 17.5
Apple Security Update: About the security content of tvOS 17.5
Product: tvOS
Version: 17.5
CVE: CVE-2024-27856
Component: WebKit
Impact: Processing a file may lead to unexpected app termination or arbitrary code execution
Description: The issue was addressed with improved checks.
Apple
CVE-2024-27856: watchOS 10.5
vendor_apple·2024-05-13·CVSS 7.8
CVE-2024-27856 [HIGH] CVE-2024-27856: watchOS 10.5
Apple Security Update: About the security content of watchOS 10.5
Product: watchOS
Version: 10.5
CVE: CVE-2024-27856
Component: WebKit
Impact: Processing a file may lead to unexpected app termination or arbitrary code execution
Description: The issue was addressed with improved checks.
Debian
CVE-2024-27856: webkit2gtk - The issue was addressed with improved checks. This issue is fixed in Safari 17.5...
vendor_debian·2024·CVSS 7.8
CVE-2024-27856 [HIGH] CVE-2024-27856: webkit2gtk - The issue was addressed with improved checks. This issue is fixed in Safari 17.5...
The issue was addressed with improved checks. This issue is fixed in Safari 17.5, iOS 16.7.8 and iPadOS 16.7.8, iOS 17.5 and iPadOS 17.5, macOS Sonoma 14.5, tvOS 17.5, visionOS 1.2, watchOS 10.5. Processing a file may lead to unexpected app termination or arbitrary code execution.
Scope: local
bookworm: resolved (fixed in 2.46.0-2~deb12u1)
bullseye: resolved (fixed in 2.46.0-1)
forky: resolved (fixed in 2.46.0-1)
sid: resolved (fixed in 2.46.0-1)
trixie: resolved (fixed in 2.46.0-1)
OSV
CVE-2024-27856: The issue was addressed with improved checks
osv·2025-01-15·CVSS 7.8
CVE-2024-27856 [HIGH] CVE-2024-27856: The issue was addressed with improved checks
The issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14.5, iOS 16.7.8 and iPadOS 16.7.8, Safari 17.5, iOS 17.5 and iPadOS 17.5, watchOS 10.5, tvOS 17.5, visionOS 1.2. Processing a file may lead to unexpected app termination or arbitrary code execution.
GHSA
GHSA-55ww-9933-hhf5: The issue was addressed with improved checks
ghsa_unreviewed·2025-01-15
CVE-2024-27856 [HIGH] CWE-94 GHSA-55ww-9933-hhf5: The issue was addressed with improved checks
The issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14.5, iOS 16.7.8 and iPadOS 16.7.8, Safari 17.5, iOS 17.5 and iPadOS 17.5, watchOS 10.5, tvOS 17.5, visionOS 1.2. Processing a file may lead to unexpected app termination or arbitrary code execution.
OSV
CVE-2024-27856: The issue was addressed with improved checks
osv·2025-01-15·CVSS 7.8
CVE-2024-27856 [HIGH] CVE-2024-27856: The issue was addressed with improved checks
The issue was addressed with improved checks. This issue is fixed in Safari 17.5, iOS 16.7.8 and iPadOS 16.7.8, iOS 17.5 and iPadOS 17.5, macOS Sonoma 14.5, tvOS 17.5, visionOS 1.2, watchOS 10.5. Processing a file may lead to unexpected app termination or arbitrary code execution.
No detection rules found.
No public exploits indexed.
2025-01-15
Published