Apple Security Bug Opens iPhone, iPad to RCE
ID: 0d97446c-5bc2-5969-bb2d-834d5c9a9c0b
STIX ID: report--0d97446c-5bc2-5969-bb2d-834d5c9a9c0b
Feed Name: Dark Reading
Apple released patches for CVE-2024-1580, an out-of-bounds write in the dav1d AV1 decoder used by Core Media and WebRTC that could allow remote code execution on many iPhone, iPad, macOS, Safari and visionOS devices; Google Project Zero reported the issue and Apple advised immediate updates. Google characterized the bug as medium severity with high attack complexity requiring local network access or proximity, and commentary suggests Apple treated the flaw as sufficiently dangerous to limit initial disclosure details.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
