CVE-2024-27834

The issue was addressed with improved checks. This issue is fixed in iOS 17.5 and iPadOS 17.5, tvOS 17.5, Safari 17.5, watchOS 10.5, macOS Sonoma 14.5. An attacker with arbitrary read and write capability may be able to bypass Pointer Authentication.
References
Link Resource
http://seclists.org/fulldisclosure/2024/May/10 Mailing List
http://seclists.org/fulldisclosure/2024/May/12 Mailing List
http://seclists.org/fulldisclosure/2024/May/16 Mailing List
http://seclists.org/fulldisclosure/2024/May/17 Mailing List
http://seclists.org/fulldisclosure/2024/May/9 Mailing List
http://www.openwall.com/lists/oss-security/2024/05/21/1 Mailing List
https://lists.fedoraproject.org/archives/list/[email protected]/message/ADCLQW54XN37VJZNYD3UKCYATJFIMYXG/ Mailing List
https://lists.fedoraproject.org/archives/list/[email protected]/message/WKIXADCW3O4R2OOSDZGPU55XQFE6NA3M/ Mailing List
https://support.apple.com/en-us/HT214101 Vendor Advisory
https://support.apple.com/en-us/HT214102 Vendor Advisory
https://support.apple.com/en-us/HT214103 Vendor Advisory
https://support.apple.com/en-us/HT214104 Vendor Advisory
https://support.apple.com/en-us/HT214106 Vendor Advisory
http://seclists.org/fulldisclosure/2024/May/10 Mailing List
http://seclists.org/fulldisclosure/2024/May/12 Mailing List
http://seclists.org/fulldisclosure/2024/May/16 Mailing List
http://seclists.org/fulldisclosure/2024/May/17 Mailing List
http://seclists.org/fulldisclosure/2024/May/9 Mailing List
http://www.openwall.com/lists/oss-security/2024/05/21/1 Mailing List
https://lists.fedoraproject.org/archives/list/[email protected]/message/ADCLQW54XN37VJZNYD3UKCYATJFIMYXG/ Mailing List
https://lists.fedoraproject.org/archives/list/[email protected]/message/WKIXADCW3O4R2OOSDZGPU55XQFE6NA3M/ Mailing List
https://support.apple.com/en-us/HT214101 Vendor Advisory
https://support.apple.com/en-us/HT214102 Vendor Advisory
https://support.apple.com/en-us/HT214103 Vendor Advisory
https://support.apple.com/en-us/HT214104 Vendor Advisory
https://support.apple.com/en-us/HT214106 Vendor Advisory
https://support.apple.com/kb/HT214100
https://support.apple.com/kb/HT214102
https://support.apple.com/kb/HT214104
https://support.apple.com/kb/HT214106
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:apple:safari:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:tvos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:watchos:*:*:*:*:*:*:*:*

Configuration 2 (hide)

OR cpe:2.3:a:webkitgtk:webkitgtk:*:*:*:*:*:*:*:*
cpe:2.3:a:wpewebkit:wpe_webkit:*:*:*:*:*:*:*:*

Configuration 3 (hide)

OR cpe:2.3:o:fedoraproject:fedora:39:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:40:*:*:*:*:*:*:*

History

04 Nov 2025, 18:16

Type Values Removed Values Added
References
  • () https://support.apple.com/kb/HT214100 -
  • () https://support.apple.com/kb/HT214102 -
  • () https://support.apple.com/kb/HT214104 -
  • () https://support.apple.com/kb/HT214106 -

Information

Published : 2024-05-14 15:13

Updated : 2025-11-04 18:16


NVD link : CVE-2024-27834

Mitre link : CVE-2024-27834

CVE.ORG link : CVE-2024-27834


JSON object : View

Products Affected

wpewebkit

  • wpe_webkit

apple

  • watchos
  • ipados
  • iphone_os
  • safari
  • tvos
  • macos

webkitgtk

  • webkitgtk

fedoraproject

  • fedora
CWE
NVD-CWE-noinfo CWE-277

Insecure Inherited Permissions