Apple Security Updates – 22 September 2024

Apple has released security updates to address multiple vulnerabilities across multiple Apple products.

The addressed vulnerabilities could allow the attacker to gain elevated privileges, bypass security restrictions, obtain sensitive information, perform denial of service attacks, or gain access to the affected systems.

Sample of the addressed vulnerabilities:

1. Apple macOS Sequoia Privilege Escalation Vulnerability (CVE-2024-40861):

  • CVSS: 7.8
  • Attack Vector: Local
  • Attack Complexity: Low
  • Privileges Required: None
  • User Interaction: Required
  • Consequences: Privilege Escalation

2. Apple macOS Ventura Denial of Service Vulnerability (CVE-2024-44160):

  • CVSS: 6.5
  • Attack Vector: Network
  • Attack Complexity: Low
  • Privileges Required: None
  • User Interaction: Required
  • Consequences: Denial of Service

The affected products:

  • Safari 18.
  • macOS Ventura 13.7.
  • macOS Sonoma 14.7.
  • macOS Sequoia 15.
Vulnerabilities
Mitigations

The enterprise should deploy this patch as soon as the testing phase is completed.

Apple Security Advisory

References