Know every vulnerabilitybefore it knows you.
DevGuard continuously monitors your dependencies and alerts you when CVEs like this one affect your stack — with real-time threat intelligence built for developers.
- Feiten
Apple heeft meerdere kwetsbaarheden verholpen in iOS en iPadOS.
- Interpretaties
De kwetsbaarheden omvatten onder andere geheugenbeheerproblemen, ongeautoriseerde toegang tot gevoelige gebruikersdata, en de mogelijkheid voor applicaties om hun sandbox-omgevingen te ontsnappen. Deze kwetsbaarheden konden leiden tot ongeautoriseerde toegang, gegevenswijzigingen, of zelfs Denial-of-Service. Voor succesvol misbruik moet de kwaadwillende het slachtoffer misleiden een malafide app te installeren of link te volgen.
- Oplossingen
Apple heeft updates uitgebracht om de kwetsbaarheden te verhelpen. Zie bijgevoegde referenties voor meer informatie.
- Kans
medium
- Schade
high
- CWE-1025
Comparison Using Wrong Factors
- CWE-697
Incorrect Comparison
- CWE-125
Out-of-bounds Read
- CWE-284
Improper Access Control
- CWE-416
Use After Free
- CWE-476
NULL Pointer Dereference
- CWE-94
Improper Control of Generation of Code ('Code Injection')
- CWE-400
Uncontrolled Resource Consumption
- CWE-863
Incorrect Authorization
- CWE-787
Out-of-bounds Write
- CWE-200
Exposure of Sensitive Information to an Unauthorized Actor
- CWE-20
Improper Input Validation
- CWE-276
Incorrect Default Permissions
- CWE-275
CWE-275
- CWE-770
Allocation of Resources Without Limits or Throttling
Continuously monitor your dependencies and get alerted when vulnerabilities like this one affect your stack.
Checkout DevGuard