logo

Apple Security Bug Opens iPhone, iPad to RCE

ID: 0d97446c-5bc2-5969-bb2d-834d5c9a9c0b

STIX ID: report--0d97446c-5bc2-5969-bb2d-834d5c9a9c0b

Feed Name: Dark Reading

Threat Score
60/100

Date Published: 2024-03-26

Date Updated: 2026-04-21

Author: Jai Vijayan, Contributing Writer

...
...

Apple released patches for CVE-2024-1580, an out-of-bounds write in the dav1d AV1 decoder used by Core Media and WebRTC that could allow remote code execution on many iPhone, iPad, macOS, Safari and visionOS devices; Google Project Zero reported the issue and Apple advised immediate updates. Google characterized the bug as medium severity with high attack complexity requiring local network access or proximity, and commentary suggests Apple treated the flaw as sufficiently dangerous to limit initial disclosure details.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.