AI description
CVE-2024-0258 is a vulnerability that was addressed by Apple through improvements in memory handling. This flaw could potentially allow an application to execute arbitrary code outside of its designated sandbox or with elevated privileges on affected systems. The issue was resolved in several Apple operating system updates, including iOS 17.4, iPadOS 17.4, macOS Sonoma 14.4, tvOS 17.4, and watchOS 10.4.
- Description
- The issue was addressed with improved memory handling. This issue is fixed in iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4, tvOS 17.4, watchOS 10.4. An app may be able to execute arbitrary code out of its sandbox or with certain elevated privileges.
- Source
- product-security@apple.com
- NVD status
- Modified
- Products
- ipad_os, iphone_os, macos, tvos, watchos
CVSS 3.1
- Type
- Primary
- Base score
- 8.6
- Impact score
- 6
- Exploitability score
- 1.8
- Vector string
- CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
- Severity
- HIGH
- nvd@nist.gov
- NVD-CWE-noinfo
- 134c704f-9b21-4f2e-91b3-4a467353bcc0
- CWE-284
- Hype score
- Not currently trending
Hi @elonmusk , 99.99% chance you never read this. 0.01% chance it becomes an interesting conversation. I built software that found a vulnerability in Apple's XPC. Apple fixed it. They credited me (CVE-2024-0258). Now I'm making the software smarter. — Ali
@ali_yabuz25
30 Jun 2026
5 Impressions
0 Retweets
0 Likes
0 Bookmarks
1 Reply
0 Quotes
🚨 Türk güvenlik araştırmacısı Ali Yabuz, Apple cihazlarını etkileyen kritik bir açığı keşfetti. 📌 CVE-2024-0258 olarak kayda geçen açık; iPhone, iPad, Mac, Apple Watch ve Apple TV’yi etkiliyordu. 📌 Apple sorunu güncellemelerle kapattı ve araştırma
@technowavecom
18 Jun 2026
91 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Ali Yabuz adlı Türk güvenlik araştırmacısı, Apple’ın iPhone, iPad, Mac, Apple Watch ve Apple TV gibi ürünlerini etkileyen kritik bir güvenlik açığı keşfetti. 📌 Apple tarafından doğrulanan ve CVE-2024-0258 olarak kayda geçen açık, uygulamaların korumal
@webtekno
18 Jun 2026
16435 Impressions
2 Retweets
46 Likes
8 Bookmarks
1 Reply
0 Quotes
Apple, CVE-2024-0258 güvenlik açığı için beni resmi olarak kredilendirdi. Açık, Apple ekosisteminde libxpc bileşeniyle ilgiliydi ve iOS 17.4 / macOS 14.4 güncellemeleriyle giderildi.
@ali_yabuz25
17 Jun 2026
2 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Apple tarafından CVE-2024-0258 için resmi olarak kredilendirilmek benim için büyük bir onur. Bu çalışma, yıllardır yazılım, reverse engineering, low-level programming ve güvenlik araştırmalarına verdiğim emeğin önemli bir karşılığı. https://t.co/avQjpjWj
@ali_yabuz25
17 Jun 2026
3 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Türk yazılımcı Ali Yabuz, Apple cihazlarında sandbox sınırlarını aşan kritik CVE-2024-0258 güvenlik açığını keşfetti. Açık, iOS 17.4 ve macOS 14.4 ile kapatıldı.
@FeryatBen
15 Jun 2026
51 Impressions
0 Retweets
1 Like
0 Bookmarks
0 Replies
0 Quotes
[
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:apple:ipad_os:*:*:*:*:*:*:*:*",
"matchCriteriaId": "CE5413B9-A1A8-499F-B047-163908202E69",
"versionEndExcluding": "17.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*",
"matchCriteriaId": "BCB4911E-7824-4C34-916D-88110CB415EB",
"versionEndExcluding": "17.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*",
"matchCriteriaId": "73160D1F-755B-46D2-969F-DF8E43BB1099",
"versionEndExcluding": "14.4",
"versionStartIncluding": "14.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:apple:tvos:*:*:*:*:*:*:*:*",
"matchCriteriaId": "BB6BA6CB-001B-4440-A9AE-473F5722F8E0",
"versionEndExcluding": "17.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:apple:watchos:*:*:*:*:*:*:*:*",
"matchCriteriaId": "5547F484-4E4B-4961-BAF8-F891D50BB4B6",
"versionEndExcluding": "10.4",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
]