CVE-2024-54540

The issue was addressed with improved input sanitization. This issue is fixed in Apple Music 1.5.0.152 for Windows. Processing maliciously crafted web content may disclose internal states of the app.
References
Link Resource
https://support.apple.com/en-us/122043 Vendor Advisory
Configurations

Configuration 1 (hide)

AND
cpe:2.3:a:apple:music:*:*:*:*:*:*:*:*
OR cpe:2.3:o:microsoft:windows_10_22h2:-:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_10_22h2:-:*:*:*:*:*:x86:*
cpe:2.3:o:microsoft:windows_11_24h2:-:*:*:*:*:*:arm64:*

History

No history.

Information

Published : 2025-01-15 20:15

Updated : 2025-03-24 18:15


NVD link : CVE-2024-54540

Mitre link : CVE-2024-54540

CVE.ORG link : CVE-2024-54540


JSON object : View

Products Affected

microsoft

  • windows_11_24h2
  • windows_10_22h2

apple

  • music
CWE
NVD-CWE-noinfo CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')