CVE-2024-54540
published 2025-01-15CVE-2024-54540: The issue was addressed with improved input sanitization. This issue is fixed in Apple Music 1.5.0.152 for Windows. Processing maliciously crafted web content…
PriorityP418medium4.3CVSS 3.1
AVNACLPRNUIRSUCLINAN
EPSS
0.21%
10.5th percentile
The issue was addressed with improved input sanitization. This issue is fixed in Apple Music 1.5.0.152 for Windows. Processing maliciously crafted web content may disclose internal states of the app.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | apple_music | < 1.5.0 | 1.5.0 |
| apple | apple_music_1.5.0.152_for_windows | — | — |
| apple | music | < 1.5.0.152 | 1.5.0.152 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Apple
CVE-2024-54540: Apple Music 1.5.0.152 for Windows
vendor_apple·2024-10-03·CVSS 4.3
CVE-2024-54540 [MEDIUM] CVE-2024-54540: Apple Music 1.5.0.152 for Windows
Apple Security Update: About the security content of Apple Music 1.5.0.152 for Windows
Product: Apple Music 1.5.0.152 for Windows
CVE: CVE-2024-54540
Component: Music
Impact: Processing maliciously crafted web content may disclose internal states of the app
Description: The issue was addressed with improved input sanitization.
GHSA
GHSA-jw5g-j894-hv7p: The issue was addressed with improved input sanitization
ghsa_unreviewed·2025-01-15
CVE-2024-54540 [MEDIUM] CWE-79 GHSA-jw5g-j894-hv7p: The issue was addressed with improved input sanitization
The issue was addressed with improved input sanitization. This issue is fixed in Apple Music 1.5.0.152 for Windows. Processing maliciously crafted web content may disclose internal states of the app.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2025-01-15
Published