CVE-2024-44285

CWE-416Use After Free8 documents4 sources
Severity
7.8HIGH
EPSS
1.4%
top 19.78%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 28

Description

A use-after-free issue was addressed with improved memory management. This issue is fixed in iOS 18.1 and iPadOS 18.1, macOS Sequoia 15.1, tvOS 18.1, visionOS 2.1, watchOS 11.1. An app may be able to cause unexpected system termination or corrupt kernel memory.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages10 packages

CVEListV5apple/tvos< 18.1
NVDapple/tvos< 18.1
CVEListV5apple/macos< 15.1
NVDapple/ipados18.018.1
CVEListV5apple/watchos< 11.1

🔴Vulnerability Details

2
CVEList
CVE-2024-44285: A use-after-free issue was addressed with improved memory management2024-10-28
GHSA
GHSA-8c5r-55p8-8p8m: A use-after-free issue was addressed with improved memory management2024-10-28

📋Vendor Advisories

5
Apple
CVE-2024-44285: tvOS18.12024-10-28
Apple
CVE-2024-44285: macOS Sequoia 15.12024-10-28
Apple
CVE-2024-44285: watchOS11.12024-10-28
Apple
CVE-2024-44285: iOS 18.1 and iPadOS 18.12024-10-28
Apple
CVE-2024-44285: visionOS2.12024-10-28
CVE-2024-44285 (HIGH CVSS 7.8) | A use-after-free issue was addresse | cvebase.io