Apple Ios 17.5 And Ipados vulnerabilities
49 known vulnerabilities affecting apple/ios_17.5_and_ipados.
Total CVEs
49
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH21MEDIUM22LOW6
Vulnerabilities
Page 2 of 3
CVE-2024-27848P3HIGHCVSS 7.8v17.52024-05-13
CVE-2024-27848 [HIGH] CVE-2024-27848: iOS 17.5 and iPadOS 17.5
Apple Security Update: About the security content of iOS 17.5 and iPadOS 17.5
Product: iOS 17.5 and iPadOS
Version: 17.5
CVE: CVE-2024-27848
Component: StorageKit
Impact: A malicious app may be able to gain root privileges
Description: This issue was addressed with improved permissions checking.
apple
CVE-2024-27838P4MEDIUMCVSS 6.5v17.52024-05-13
CVE-2024-27838 [MEDIUM] CVE-2024-27838: iOS 17.5 and iPadOS 17.5
Apple Security Update: About the security content of iOS 17.5 and iPadOS 17.5
Product: iOS 17.5 and iPadOS
Version: 17.5
CVE: CVE-2024-27838
Component: WebKit
Impact: A maliciously crafted webpage may be able to fingerprint the user
Description: The issue was addressed by adding additional logic.
apple
CVE-2024-27823P4MEDIUMCVSS 5.9v17.52024-05-13
CVE-2024-27823 [MEDIUM] CVE-2024-27823: iOS 17.5 and iPadOS 17.5
Apple Security Update: About the security content of iOS 17.5 and iPadOS 17.5
Product: iOS 17.5 and iPadOS
Version: 17.5
CVE: CVE-2024-27823
Component: Kernel
Impact: An attacker in a privileged network position may be able to spoof network packets
Description: A race condition was addressed with improved locking.
apple
CVE-2024-27850P4MEDIUMCVSS 6.5v17.52024-05-13
CVE-2024-27850 [MEDIUM] CVE-2024-27850: iOS 17.5 and iPadOS 17.5
Apple Security Update: About the security content of iOS 17.5 and iPadOS 17.5
Product: iOS 17.5 and iPadOS
Version: 17.5
CVE: CVE-2024-27850
Component: WebKit
Impact: A maliciously crafted webpage may be able to fingerprint the user
Description: This issue was addressed with improvements to the noise injection algorithm.
apple
CVE-2024-27830P4MEDIUMCVSS 6.5v17.52024-05-13
CVE-2024-27830 [MEDIUM] CVE-2024-27830: iOS 17.5 and iPadOS 17.5
Apple Security Update: About the security content of iOS 17.5 and iPadOS 17.5
Product: iOS 17.5 and iPadOS
Version: 17.5
CVE: CVE-2024-27830
Component: WebKit Canvas
Impact: A maliciously crafted webpage may be able to fingerprint the user
Description: This issue was addressed through improved state management.
apple
CVE-2024-27800P4MEDIUMCVSS 6.5v17.52024-05-13
CVE-2024-27800 [MEDIUM] CVE-2024-27800: iOS 17.5 and iPadOS 17.5
Apple Security Update: About the security content of iOS 17.5 and iPadOS 17.5
Product: iOS 17.5 and iPadOS
Version: 17.5
CVE: CVE-2024-27800
Component: Messages
Impact: Processing a maliciously crafted message may lead to a denial-of-service
Description: This issue was addressed by removing the vulnerable code.
apple
CVE-2024-27852P4MEDIUMCVSS 6.5v17.52024-05-13
CVE-2024-27852 [MEDIUM] CVE-2024-27852: iOS 17.5 and iPadOS 17.5
Apple Security Update: About the security content of iOS 17.5 and iPadOS 17.5
Product: iOS 17.5 and iPadOS
Version: 17.5
CVE: CVE-2024-27852
Component: MarketplaceKit
Impact: A maliciously crafted webpage may be able to distribute a script that tracks users on other webpages
Description: A privacy issue was addressed with improved client ID handling for alternative app marketplaces.
apple
CVE-2024-27834P4MEDIUMCVSS 5.5v17.52024-05-13
CVE-2024-27834 [MEDIUM] CVE-2024-27834: iOS 17.5 and iPadOS 17.5
Apple Security Update: About the security content of iOS 17.5 and iPadOS 17.5
Product: iOS 17.5 and iPadOS
Version: 17.5
CVE: CVE-2024-27834
Component: WebKit
Impact: An attacker with arbitrary read and write capability may be able to bypass Pointer Authentication
Description: The issue was addressed with improved checks.
apple
CVE-2024-27840P4MEDIUMCVSS 6.3v17.52024-05-13
CVE-2024-27840 [MEDIUM] CVE-2024-27840: iOS 17.5 and iPadOS 17.5
Apple Security Update: About the security content of iOS 17.5 and iPadOS 17.5
Product: iOS 17.5 and iPadOS
Version: 17.5
CVE: CVE-2024-27840
Component: Kernel
Impact: An attacker that has already achieved kernel code execution may be able to bypass kernel memory protections
Description: The issue was addressed with improved memory handling.
apple
CVE-2023-42893P4MEDIUMCVSS 5.5v17.52024-05-13
CVE-2023-42893 [MEDIUM] CVE-2023-42893: iOS 17.5 and iPadOS 17.5
Apple Security Update: About the security content of iOS 17.5 and iPadOS 17.5
Product: iOS 17.5 and iPadOS
Version: 17.5
CVE: CVE-2023-42893
Component: Libsystem
Impact: An app may be able to access protected user data
Description: A permissions issue was addressed by removing vulnerable code and adding additional checks.
apple
CVE-2024-27884P4MEDIUMCVSS 5.5v17.52024-05-13
CVE-2024-27884 [MEDIUM] CVE-2024-27884: iOS 17.5 and iPadOS 17.5
Apple Security Update: About the security content of iOS 17.5 and iPadOS 17.5
Product: iOS 17.5 and iPadOS
Version: 17.5
CVE: CVE-2024-27884
Component: Transparency
Impact: An app may be able to access user-sensitive data
Description: This issue was addressed with a new entitlement.
apple
CVE-2024-27816P4MEDIUMCVSS 5.5v17.52024-05-13
CVE-2024-27816 [MEDIUM] CVE-2024-27816: iOS 17.5 and iPadOS 17.5
Apple Security Update: About the security content of iOS 17.5 and iPadOS 17.5
Product: iOS 17.5 and iPadOS
Version: 17.5
CVE: CVE-2024-27816
Component: AppleMobileFileIntegrity
Impact: An attacker may be able to access user data
Description: A logic issue was addressed with improved checks.
apple
CVE-2024-27810P4MEDIUMCVSS 5.5v17.52024-05-13
CVE-2024-27810 [MEDIUM] CVE-2024-27810: iOS 17.5 and iPadOS 17.5
Apple Security Update: About the security content of iOS 17.5 and iPadOS 17.5
Product: iOS 17.5 and iPadOS
Version: 17.5
CVE: CVE-2024-27810
Component: Maps
Impact: An app may be able to read sensitive location information
Description: A path handling issue was addressed with improved validation.
apple
CVE-2024-27806P4MEDIUMCVSS 5.5v17.52024-05-13
CVE-2024-27806 [MEDIUM] CVE-2024-27806: iOS 17.5 and iPadOS 17.5
Apple Security Update: About the security content of iOS 17.5 and iPadOS 17.5
Product: iOS 17.5 and iPadOS
Version: 17.5
CVE: CVE-2024-27806
Component: CVE-2024-27806
apple
CVE-2024-27805P4MEDIUMCVSS 5.5v17.52024-05-13
CVE-2024-27805 [MEDIUM] CVE-2024-27805: iOS 17.5 and iPadOS 17.5
Apple Security Update: About the security content of iOS 17.5 and iPadOS 17.5
Product: iOS 17.5 and iPadOS
Version: 17.5
CVE: CVE-2024-27805
Component: Core Data
Impact: An app may be able to access sensitive user data
Description: An issue was addressed with improved validation of environment variables.
apple
CVE-2024-27804P4MEDIUMCVSS 5.5v17.52024-05-13
CVE-2024-27804 [MEDIUM] CVE-2024-27804: iOS 17.5 and iPadOS 17.5
Apple Security Update: About the security content of iOS 17.5 and iPadOS 17.5
Product: iOS 17.5 and iPadOS
Version: 17.5
CVE: CVE-2024-27804
Component: AppleAVD
Impact: An app may be able to cause unexpected system termination
Description: The issue was addressed with improved memory handling.
apple
CVE-2024-27841P4MEDIUMCVSS 5.5v17.52024-05-13
CVE-2024-27841 [MEDIUM] CVE-2024-27841: iOS 17.5 and iPadOS 17.5
Apple Security Update: About the security content of iOS 17.5 and iPadOS 17.5
Product: iOS 17.5 and iPadOS
Version: 17.5
CVE: CVE-2024-27841
Component: AVEVideoEncoder
Impact: An app may be able to disclose kernel memory
Description: The issue was addressed with improved memory handling.
apple
CVE-2024-23282P4MEDIUMCVSS 5.5v17.52024-05-13
CVE-2024-23282 [MEDIUM] CVE-2024-23282: iOS 17.5 and iPadOS 17.5
Apple Security Update: About the security content of iOS 17.5 and iPadOS 17.5
Product: iOS 17.5 and iPadOS
Version: 17.5
CVE: CVE-2024-23282
Component: Mail
Impact: A maliciously crafted email may be able to initiate FaceTime calls without user authorization
Description: The issue was addressed with improved checks.
apple
CVE-2024-27847P4MEDIUMCVSS 5.5v17.52024-05-13
CVE-2024-27847 [MEDIUM] CVE-2024-27847: iOS 17.5 and iPadOS 17.5
Apple Security Update: About the security content of iOS 17.5 and iPadOS 17.5
Product: iOS 17.5 and iPadOS
Version: 17.5
CVE: CVE-2024-27847
Component: Sync Services
Impact: An app may be able to bypass Privacy preferences
Description: This issue was addressed with improved checks
apple
CVE-2024-27821P4MEDIUMCVSS 4.7v17.52024-05-13
CVE-2024-27821 [MEDIUM] CVE-2024-27821: iOS 17.5 and iPadOS 17.5
Apple Security Update: About the security content of iOS 17.5 and iPadOS 17.5
Product: iOS 17.5 and iPadOS
Version: 17.5
CVE: CVE-2024-27821
Component: Shortcuts
Impact: A shortcut may output sensitive user data without consent
Description: A path handling issue was addressed with improved validation.
apple