CVE-2024-54499
published 2025-01-27CVE-2024-54499: A use-after-free issue was addressed with improved memory management. This issue is fixed in iOS 18.2 and iPadOS 18.2, macOS Sequoia 15.2, tvOS 18.2, visionOS…
PriorityP350high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
EPSS
0.61%
45.3th percentile
A use-after-free issue was addressed with improved memory management. This issue is fixed in iOS 18.2 and iPadOS 18.2, macOS Sequoia 15.2, tvOS 18.2, visionOS 2.2, watchOS 11.2. Processing a maliciously crafted image may lead to arbitrary code execution.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | ios18.2_and_ipados18.2 | — | — |
| apple | ios_and_ipados | < 18.2 | 18.2 |
| apple | ipados | < 18.2 | 18.2 |
| apple | iphone_os | < 18.2 | 18.2 |
| apple | macos | < 15.2 | 15.2 |
| apple | macos_sequoia | — | — |
| apple | tvos | < 18.2 | 18.2 |
| apple | tvos18.2 | — | — |
| apple | visionos | < 2.2 | 2.2 |
| apple | visionos2.2 | — | — |
| apple | watchos | < 11.2 | 11.2 |
| apple | watchos11.2 | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Apple
CVE-2024-54499: macOS Sequoia 15.2
vendor_apple·2024-12-11·CVSS 8.8
CVE-2024-54499 [HIGH] CVE-2024-54499: macOS Sequoia 15.2
Apple Security Update: About the security content of macOS Sequoia 15.2
Product: macOS Sequoia
Version: 15.2
CVE: CVE-2024-54499
Component: ImageIO
Impact: Processing a maliciously crafted image may lead to arbitrary code execution
Description: A use-after-free issue was addressed with improved memory management.
Apple
CVE-2024-54499: watchOS11.2
vendor_apple·2024-12-11·CVSS 8.8
CVE-2024-54499 [HIGH] CVE-2024-54499: watchOS11.2
Apple Security Update: About the security content of watchOS11.2
Product: watchOS11.2
CVE: CVE-2024-54499
Component: ImageIO
Impact: Processing a maliciously crafted image may lead to arbitrary code execution
Description: A use-after-free issue was addressed with improved memory management.
Apple
CVE-2024-54499: iOS18.2 and iPadOS18.2
vendor_apple·2024-12-11·CVSS 8.8
CVE-2024-54499 [HIGH] CVE-2024-54499: iOS18.2 and iPadOS18.2
Apple Security Update: About the security content of iOS18.2 and iPadOS18.2
Product: iOS18.2 and iPadOS18.2
CVE: CVE-2024-54499
Component: ImageIO
Impact: Processing a maliciously crafted image may lead to arbitrary code execution
Description: A use-after-free issue was addressed with improved memory management.
Apple
CVE-2024-54499: tvOS18.2
vendor_apple·2024-12-11·CVSS 8.8
CVE-2024-54499 [HIGH] CVE-2024-54499: tvOS18.2
Apple Security Update: About the security content of tvOS18.2
Product: tvOS18.2
CVE: CVE-2024-54499
Component: ImageIO
Impact: Processing a maliciously crafted image may lead to arbitrary code execution
Description: A use-after-free issue was addressed with improved memory management.
Apple
CVE-2024-54499: visionOS2.2
vendor_apple·2024-12-11·CVSS 8.8
CVE-2024-54499 [HIGH] CVE-2024-54499: visionOS2.2
Apple Security Update: About the security content of visionOS2.2
Product: visionOS2.2
CVE: CVE-2024-54499
Component: ImageIO
Impact: Processing a maliciously crafted image may lead to arbitrary code execution
Description: A use-after-free issue was addressed with improved memory management.
GHSA
GHSA-5r86-xcpg-678m: A use-after-free issue was addressed with improved memory management
ghsa_unreviewed·2025-01-28
CVE-2024-54499 [HIGH] CWE-416 GHSA-5r86-xcpg-678m: A use-after-free issue was addressed with improved memory management
A use-after-free issue was addressed with improved memory management. This issue is fixed in visionOS 2.2, tvOS 18.2, watchOS 11.2, iOS 18.2 and iPadOS 18.2, macOS Sequoia 15.2. Processing a maliciously crafted image may lead to arbitrary code execution.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2025-01-27
Published