Category: visionOS
-
Apple zero-day vulnerability (CVE-2025-24085)
CVE-2025-24085 is a zero-day vulnerability that arises from a “use after free” issue in Apple’s CoreMedia framework. This flaw affects multiple Apple operating systems, including iOS, iPadOS, macOS, tvOS, visionOS, and watchOS. This vulnerability occurs when memory that has already been freed is improperly accessed, potentially leading to arbitrary code execution or privilege escalation. Apple…
-
Apple zero-day vulnerability (CVE-2024-44309)
CVE-2024-44309 is a zero-day vulnerability addressed in Apple products, including Safari, iOS, iPadOS, macOS, and visionOS. Exploiting this flaw by processing maliciously crafted web content may lead to a cross-site scripting (XSS) attack. It has been actively exploited on Intel-based Mac systems. This issue is fixed in Safari 18.1.1, iOS 17.7.2 and iPadOS 17.7.2, macOS…
-
Apple zero-day vulnerability (CVE-2024-44308)
CVE-2024-44308 is a zero-day vulnerability addressed in Apple products, including Safari, iOS, iPadOS, macOS, and visionOS. Exploiting this flaw by processing maliciously crafted web content could lead to arbitrary code execution. It has been actively exploited on Intel-based Mac systems. This issue is fixed in Safari 18.1.1, iOS 17.7.2 and iPadOS 17.7.2, macOS Sequoia 15.1.1,…
-
Apple security vulnerability (CVE-2024-44215)
CVE-2024-44215 is a vulnerability in Apple’s ImageIO component. It allows unauthorized disclosure of memory contents through crafted image files, which could expose sensitive information if exploited. This flaw affects multiple Apple platforms, including macOS, iOS, iPadOS, and watchOS. This issue is fixed in tvOS 18.1, iOS 18.1 and iPadOS 18.1, iOS 17.7.1 and iPadOS 17.7.1,…
-
Apple security vulnerability (CVE-2024-44259)
CVE-2024-44259 is a high-severity vulnerability impacting Apple’s Safari browser and several Apple operating systems, including macOS Sequoia, iOS, iPadOS, and visionOS. This vulnerability arises from a trust relationship flaw that could enable an attacker to download malicious content without proper authorization. Its potential impact is serious, as it affects confidentiality, integrity, and availability. Apple mitigated…
-
Apple security vulnerability (CVE-2024-44206)
CVE-2024-44206 is a vulnerability in Apple’s WebKit, related specifically to the handling of URL protocols. This issue could potentially allow a bypass of web content restrictions on affected devices, exposing users to restricted content if exploited. Apple addressed this vulnerability by improving the logic for URL handling.This issue is fixed in tvOS 17.6, visionOS 1.3,…