CVE-2024-27844
https://notcve.org/view.php?id=CVE-2024-27844
The issue was addressed with improved checks. This issue is fixed in visionOS 1.2, macOS Sonoma 14.5, Safari 17.5. A website's permission dialog may persist after navigation away from the site. El problema se solucionó con controles mejorados. Este problema se solucionó en visionOS 1.2, macOS Sonoma 14.5, Safari 17.5. • http://seclists.org/fulldisclosure/2024/Jun/5 https://support.apple.com/en-us/HT214103 https://support.apple.com/en-us/HT214106 https://support.apple.com/en-us/HT214108 https://support.apple.com/kb/HT214103 https://support.apple.com/kb/HT214106 https://support.apple.com/kb/HT214108 •
CVE-2024-27848
https://notcve.org/view.php?id=CVE-2024-27848
This issue was addressed with improved permissions checking. This issue is fixed in macOS Sonoma 14.5, iOS 17.5 and iPadOS 17.5. A malicious app may be able to gain root privileges. Este problema se solucionó mejorando la verificación de permisos. Este problema se solucionó en macOS Sonoma 14.5, iOS 17.5 y iPadOS 17.5. • https://support.apple.com/en-us/HT214101 https://support.apple.com/en-us/HT214106 https://support.apple.com/kb/HT214101 https://support.apple.com/kb/HT214106 • CWE-277: Insecure Inherited Permissions CWE-863: Incorrect Authorization •
CVE-2022-48578
https://notcve.org/view.php?id=CVE-2022-48578
An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Monterey 12.5. Processing an AppleScript may result in unexpected termination or disclosure of process memory. Se solucionó una lectura fuera de los límites con una verificación de los límites mejorada. Este problema se solucionó en macOS Monterey 12.5. • https://support.apple.com/en-us/HT213345 • CWE-125: Out-of-bounds Read •
CVE-2022-32933 – webkitgtk: A website may able to track visited websites in private browsing
https://notcve.org/view.php?id=CVE-2022-32933
An information disclosure issue was addressed by removing the vulnerable code. This issue is fixed in macOS Monterey 12.5. A website may be able to track the websites a user visited in Safari private browsing mode. Se solucionó un problema de divulgación de información eliminando el código vulnerable. Este problema se solucionó en macOS Monterey 12.5. • https://support.apple.com/en-us/HT213345 https://access.redhat.com/security/cve/CVE-2022-32933 https://bugzilla.redhat.com/show_bug.cgi?id=2271441 • CWE-841: Improper Enforcement of Behavioral Workflow •
CVE-2022-48683
https://notcve.org/view.php?id=CVE-2022-48683
An access issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Ventura 13. An app may be able to break out of its sandbox. Se solucionó un problema de acceso con restricciones adicionales de la zona de pruebas. Este problema se solucionó en macOS Ventura 13. • https://support.apple.com/en-us/HT213488 • CWE-284: Improper Access Control •