8.1
CVE-2024-27834
- EPSS 0.01%
- Veröffentlicht 14.05.2024 15:13:06
- Zuletzt bearbeitet 04.11.2025 18:16:14
- Quelle product-security@apple.com
- CVE-Watchlists
- Unerledigt
The issue was addressed with improved checks. This issue is fixed in iOS 17.5 and iPadOS 17.5, tvOS 17.5, Safari 17.5, watchOS 10.5, macOS Sonoma 14.5. An attacker with arbitrary read and write capability may be able to bypass Pointer Authentication.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Wpewebkit ≫ Wpe Webkit Version < 2.44.2
Fedoraproject ≫ Fedora Version39
Fedoraproject ≫ Fedora Version40
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.01% | 0.003 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 5.5 | 1.8 | 3.6 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
|
| 134c704f-9b21-4f2e-91b3-4a467353bcc0 | 8.1 | 1.4 | 6 |
CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
|
CWE-277 Insecure Inherited Permissions
A product defines a set of insecure permissions that are inherited by objects that are created by the program.