Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2024-44258


This issue was addressed with improved handling of symlinks. This issue is fixed in iOS 18.1 and iPadOS 18.1, iOS 17.7.1 and iPadOS 17.7.1, visionOS 2.1, tvOS 18.1. Restoring a maliciously crafted backup file may lead to modification of protected system files.


Published

2024-10-28T21:15:07.083

Last Modified

2024-11-06T14:35:02.583

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 7.1 (HIGH)

Weaknesses
  • Type: Primary
    CWE-59
  • Type: Secondary
    CWE-59

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System apple ipados < 17.7.1 Yes
Operating System apple ipados < 18.1 Yes
Operating System apple iphone_os < 17.7.1 Yes
Operating System apple iphone_os < 18.1 Yes
Operating System apple tvos < 18.1 Yes
Operating System apple visionos < 2.1 Yes

References