CVE-2024-27833

high

Description

An integer overflow was addressed with improved input validation. This issue is fixed in tvOS 17.5, iOS 16.7.8 and iPadOS 16.7.8, visionOS 1.2, Safari 17.5, iOS 17.5 and iPadOS 17.5. Processing maliciously crafted web content may lead to arbitrary code execution.

References

https://support.apple.com/en-us/HT214108

https://support.apple.com/en-us/HT214103

https://support.apple.com/en-us/HT214102

https://support.apple.com/en-us/HT214101

https://support.apple.com/en-us/HT214100

http://seclists.org/fulldisclosure/2024/Jun/5

Details

Source: Mitre, NVD

Published: 2024-06-10

Updated: 2024-07-03

Risk Information

CVSS v2

Base Score: 10

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

Severity: Critical

CVSS v3

Base Score: 8.8

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Severity: High