CVE-2024-54529

Published Dec 12, 2024

Last updated 5 months ago

CVSS high 7.8
macOS
Mobile device

Overview

AI description

Automated description summarized from trusted sources.

CVE-2024-54529 is a logic flaw identified in Apple macOS, specifically within its Audio component. This vulnerability enables an application to execute arbitrary code with kernel-level privileges. The underlying cause is attributed to insufficient validation or improper checks within the kernel code, allowing a local application to escalate its privileges beyond its intended scope. Disclosed on December 11, 2024, this issue was discovered by Dillon Franke in collaboration with Google Project Zero. Apple has since addressed CVE-2024-54529 by implementing improved checks. The fix is available in macOS Sequoia 15.2, macOS Ventura 13.7.2, and macOS Sonoma 14.7.2.

Description
A logic issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.2, macOS Sonoma 14.7.2, macOS Ventura 13.7.2. An app may be able to execute arbitrary code out of its sandbox or with certain elevated privileges.
Source
product-security@apple.com
NVD status
Modified
Products
macos

Risk scores

CVSS 3.1

Type
Primary
Base score
7.8
Impact score
5.9
Exploitability score
1.8
Vector string
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Severity
HIGH

Weaknesses

nvd@nist.gov
NVD-CWE-noinfo
134c704f-9b21-4f2e-91b3-4a467353bcc0
CWE-94

Social media

Hype score
Not currently trending
  1. Google Project Zero detailed how CVE-2024-54529 in macOS coreaudiod goes from a type-confusion crash to a working exploit. https://t.co/bFZxkFy4fP

    @Cyb3rR3s34rch

    8 Aug 2026

    33 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  2. Google Project Zero detailed exploitation of CVE-2024-54529, a type confusion in macOS coreaudiod’s CoreAudio Mach service that can be turned from a crash into a working exploit. https://t.co/bFZxkFy4fP

    @Cyb3rR3s34rch

    8 Aug 2026

    35 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  3. Google Project Zero published a full exploit walkthrough for CVE-2024-54529, a type confusion in macOS coreaudiod reached via the CoreAudio Mach service. https://t.co/bFZxkFy4fP

    @Cyb3rR3s34rch

    8 Aug 2026

    31 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  4. Google Project Zero turned CVE-2024-54529—a type confusion in macOS coreaudiod—from a crash into a working exploit, underscoring risk in a privileged system audio daemon. https://t.co/bFZxkFy4fP

    @Cyb3rR3s34rch

    8 Aug 2026

    34 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  5. Google Project Zero detailed a full exploit path for CVE-2024-54529, a type confusion in macOS coreaudiod’s CoreAudio Mach service that turns a crash into a working local exploit. https://t.co/bFZxkFy4fP

    @Cyb3rR3s34rch

    8 Aug 2026

    31 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  6. Google Project Zero published a full exploit write-up for CVE-2024-54529, a type confusion in macOS CoreAudio’s coreaudiod that they turned from a crash into a working exploit. https://t.co/bFZxkFy4fP

    @Cyb3rR3s34rch

    8 Aug 2026

    26 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  7. Google Project Zero published a full exploit walkthrough for CVE-2024-54529, a type confusion bug in macOS coreaudiod reached over Mach IPC. https://t.co/bFZxkFy4fP

    @Cyb3rR3s34rch

    8 Aug 2026

    32 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  8. Project Zero detailed a working exploit for CVE-2024-54529, a type confusion in macOS coreaudiod’s CoreAudio Mach path—local attack surface that turned a crash into reliable code abuse. https://t.co/bFZxkFy4fP

    @Cyb3rR3s34rch

    8 Aug 2026

    37 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  9. 🔒 #CyberSecurity CVE-2024-54529: macOS Coreaudiod Type Confusion Exploitation – Detection and Ha… "Google Project Zero's latest research, "Breaking the Sound Barrier, Part II,"…" 🔗 https://t.co/oGVRTipsUc #CyberSecurity #ThreatIntel #sigmarule #kqldetection #threa

    @SecurityAr58409

    15 Apr 2026

    39 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  10. 🔒 #CyberSecurity Defending Against CVE-2024-54529: The macOS coreaudiod Type Confusion Vulnerabi… "Cybersecurity researchers at Google Project Zero have recently provided an in-depth…" 🔗 https://t.co/CAgXiVOiN7 #CyberSecurity #ThreatIntel #vulnerability #cve #patch

    @SecurityAr58409

    15 Apr 2026

    23 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  11. 🔒 #CyberSecurity Defending Against CVE-2024-54529: Protecting macOS from Core Audio Exploits "Recent research from Google Project Zero has shed light on a significant security flaw within…" 🔗 https://t.co/un8odcd9qr #CyberSecurity #ThreatIntel #vulnerability #cve #pat

    @SecurityAr58409

    15 Apr 2026

    26 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  12. 🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: Breaking the Sound Barrier, Part II: Exploiting CVE-2024-54529 Intel Report: https://t.co/0ycUz8OANX

    @cyberbivash

    22 Mar 2026

    26 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  13. CVE-2024-54529 was patched. To celebrate, I'm open-sourcing my full PoC exploit for this CoreAudio type confusion vulnerability 🔊 The code is right here! Enjoy: https://t.co/XvWXwXmPg6 https://t.co/aD9NjL70wJ

    @hermes_tool1

    2 Feb 2026

    3954 Impressions

    4 Retweets

    36 Likes

    30 Bookmarks

    2 Replies

    0 Quotes

  14. It's been just over a year since CVE-2024-54529 was patched. To celebrate, I'm open-sourcing my full PoC exploit for this CoreAudio type confusion vulnerability 🔊 The code is right here! Enjoy: https://t.co/GRvILp6C84 https://t.co/1tu0qyHsQg

    @dillon_franke

    30 Jan 2026

    22068 Impressions

    41 Retweets

    222 Likes

    120 Bookmarks

    4 Replies

    1 Quote

  15. Breaking the Sound Barrier, Part II: Exploiting CVE-2024-54529 https://t.co/Sozi4r5TcL

    @ProjectZeroBugs

    30 Jan 2026

    3471 Impressions

    13 Retweets

    50 Likes

    20 Bookmarks

    1 Reply

    0 Quotes

  16. CVE-2024-54529 A logic issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.2, macOS Ventura 13.7.2, macOS Sonoma 14.7.2. An app may be able to execute … https://t.co/zlYhQ0Qnxw

    @CVEnew

    12 Dec 2024

    234 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  17. CVE-2024-54529 Kernel Privilege Logic Flaw in macOS Sequoia, Ventura, and Sonoma... https://t.co/Vqdc4wHjiJ Vulnerability Alert Subscriptions: https://t.co/hrQhy5uz4x

    @VulmonFeeds

    12 Dec 2024

    10 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

Configurations