cbcvebase.
CVE-2024-44258
published 2024-10-28

CVE-2024-44258: This issue was addressed with improved handling of symlinks. This issue is fixed in iOS 17.7.1 and iPadOS 17.7.1, iOS 18.1 and iPadOS 18.1, tvOS 18.1, visionOS…

high7.1CVSS 3.1
AVLACLPRNUIRSUCNIHAH
This issue was addressed with improved handling of symlinks. This issue is fixed in iOS 17.7.1 and iPadOS 17.7.1, iOS 18.1 and iPadOS 18.1, tvOS 18.1, visionOS 2.1. Restoring a maliciously crafted backup file may lead to modification of protected system files.

Affected

12 ranges
VendorProductVersion rangeFixed in
appleios_17.7.1_and_ipados
appleios_18.1_and_ipados
appleios_and_ipados< 17.7.117.7.1
appleios_and_ipados< 18.118.1
appleipados< 17.7.117.7.1
appleipados>= 18.0 < 18.118.1
appleiphone_os< 17.7.117.7.1
appleiphone_os>= 18.0 < 18.118.1
appletvos< 18.118.1
appletvos18.1
applevisionos< 2.12.1
applevisionos2.1

CVSS provenance

nvdv3.17.1HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H
vulncheck7.1HIGH