Apple fixes Safari WebKit zero-day flaw exploited at Pwn2Own
ID: 1d383d17-8ee3-5d24-aa20-d825b6fe7397
STIX ID: report--1d383d17-8ee3-5d24-aa20-d825b6fe7397
Feed Name: Bleeping Computer
Threat Score
Apple released patches addressing a Safari zero-day (CVE-2024-27834) exploited at Pwn2Own Vancouver 2024 to achieve remote code execution by bypassing pointer authentication on arm64e; the flaw was reported by researcher Manfred Paul (via Trend Micro's ZDI) and fixes are available for macOS Monterey and Ventura, while coverage for other Apple platforms was not yet confirmed.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
