CVE-2024-0258

Published Mar 8, 2024

Last updated 4 months ago

Overview

AI description

Automated description summarized from trusted sources.

CVE-2024-0258 is a vulnerability that was addressed by Apple through improvements in memory handling. This flaw could potentially allow an application to execute arbitrary code outside of its designated sandbox or with elevated privileges on affected systems. The issue was resolved in several Apple operating system updates, including iOS 17.4, iPadOS 17.4, macOS Sonoma 14.4, tvOS 17.4, and watchOS 10.4.

Description
The issue was addressed with improved memory handling. This issue is fixed in iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4, tvOS 17.4, watchOS 10.4. An app may be able to execute arbitrary code out of its sandbox or with certain elevated privileges.
Source
product-security@apple.com
NVD status
Modified
Products
ipad_os, iphone_os, macos, tvos, watchos

Risk scores

CVSS 3.1

Type
Primary
Base score
8.6
Impact score
6
Exploitability score
1.8
Vector string
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Severity
HIGH

Weaknesses

nvd@nist.gov
NVD-CWE-noinfo
134c704f-9b21-4f2e-91b3-4a467353bcc0
CWE-284

Social media

Hype score
Not currently trending
  1. Hi @elonmusk , 99.99% chance you never read this. 0.01% chance it becomes an interesting conversation. I built software that found a vulnerability in Apple's XPC. Apple fixed it. They credited me (CVE-2024-0258). Now I'm making the software smarter. — Ali

    @ali_yabuz25

    30 Jun 2026

    5 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  2. 🚨 Türk güvenlik araştırmacısı Ali Yabuz, Apple cihazlarını etkileyen kritik bir açığı keşfetti. 📌 CVE-2024-0258 olarak kayda geçen açık; iPhone, iPad, Mac, Apple Watch ve Apple TV’yi etkiliyordu. 📌 Apple sorunu güncellemelerle kapattı ve araştırma

    @technowavecom

    18 Jun 2026

    91 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  3. Ali Yabuz adlı Türk güvenlik araştırmacısı, Apple’ın iPhone, iPad, Mac, Apple Watch ve Apple TV gibi ürünlerini etkileyen kritik bir güvenlik açığı keşfetti. 📌 Apple tarafından doğrulanan ve CVE-2024-0258 olarak kayda geçen açık, uygulamaların korumal

    @webtekno

    18 Jun 2026

    16435 Impressions

    2 Retweets

    46 Likes

    8 Bookmarks

    1 Reply

    0 Quotes

  4. Apple, CVE-2024-0258 güvenlik açığı için beni resmi olarak kredilendirdi. Açık, Apple ekosisteminde libxpc bileşeniyle ilgiliydi ve iOS 17.4 / macOS 14.4 güncellemeleriyle giderildi.

    @ali_yabuz25

    17 Jun 2026

    2 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  5. Apple tarafından CVE-2024-0258 için resmi olarak kredilendirilmek benim için büyük bir onur. Bu çalışma, yıllardır yazılım, reverse engineering, low-level programming ve güvenlik araştırmalarına verdiğim emeğin önemli bir karşılığı. https://t.co/avQjpjWj

    @ali_yabuz25

    17 Jun 2026

    3 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  6. Türk yazılımcı Ali Yabuz, Apple cihazlarında sandbox sınırlarını aşan kritik CVE-2024-0258 güvenlik açığını keşfetti. Açık, iOS 17.4 ve macOS 14.4 ile kapatıldı.

    @FeryatBen

    15 Jun 2026

    51 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

Configurations