Apple releases iOS & iPadOS 17.5, watchOS 10.5 and macOS Sonoma 14.5 which include privacy & security improvements

https://9to5mac.com/2024/05/13/apple-releases-ios-17-5-with-new-games-in-news-cross-platform-tracking-detection-more/

iOS 17.5 release notes

(…)

Tracking Notifications

Cross-Platform Tracking Detection delivers notifications to users if a compatible Bluetooth tracker they do not own is moving with them, regardless of what operating system the device is paired with


Other software updates released today out-of-beta include the following:

watchOS 10.5
HomePod 17.5
tvOS 17.5
macOS 14.5
macOS 13.6.7

HomePod users can expect “performance and stability improvements,” according to release notes. macOS focuses on security updates.

Privacy & security improvements included in these updates:

AppleAVD

Available for: iPhone XS and later, iPad Pro 12.9-inch 2nd generation and later, iPad Pro 10.5-inch, iPad Pro 11-inch 1st generation and later, iPad Air 3rd generation and later, iPad 6th generation and later, and iPad mini 5th generation and later

Impact: An app may be able to execute arbitrary code with kernel privileges

Description: The issue was addressed with improved memory handling.

CVE-2024-27804: Meysam Firouzi

AppleMobileFileIntegrity

Available for: iPhone XS and later, iPad Pro 12.9-inch 2nd generation and later, iPad Pro 10.5-inch, iPad Pro 11-inch 1st generation and later, iPad Air 3rd generation and later, iPad 6th generation and later, and iPad mini 5th generation and later

Impact: An attacker may be able to access user data

Description: A logic issue was addressed with improved checks.

CVE-2024-27816: Mickey Jin

AVEVideoEncoder

Available for: iPhone XS and later, iPad Pro 12.9-inch 2nd generation and later, iPad Pro 10.5-inch, iPad Pro 11-inch 1st generation and later, iPad Air 3rd generation and later, iPad 6th generation and later, and iPad mini 5th generation and later

Impact: An app may be able to disclose kernel memory

Description: The issue was addressed with improved memory handling.

CVE-2024-27841: an anonymous researcher

Find My

Available for: iPhone XS and later, iPad Pro 12.9-inch 2nd generation and later, iPad Pro 10.5-inch, iPad Pro 11-inch 1st generation and later, iPad Air 3rd generation and later, iPad 6th generation and later, and iPad mini 5th generation and later

Impact: A malicious application may be able to determine a user’s current location

Description: A privacy issue was addressed by moving sensitive data to a more secure location.

CVE-2024-27839: Alexander Heinrich, SEEMOO, TU Darmstadt, and Shai Mishali

Kernel

Available for: iPhone XS and later, iPad Pro 12.9-inch 2nd generation and later, iPad Pro 10.5-inch, iPad Pro 11-inch 1st generation and later, iPad Air 3rd generation and later, iPad 6th generation and later, and iPad mini 5th generation and later

Impact: An attacker may be able to cause unexpected app termination or arbitrary code execution

Description: The issue was addressed with improved memory handling.

CVE-2024-27818: pattern-f of Ant Security Light-Year Lab

Libsystem

Available for: iPhone XS and later, iPad Pro 12.9-inch 2nd generation and later, iPad Pro 10.5-inch, iPad Pro 11-inch 1st generation and later, iPad Air 3rd generation and later, iPad 6th generation and later, and iPad mini 5th generation and later

Impact: An app may be able to access protected user data

Description: A permissions issue was addressed by removing vulnerable code and adding additional checks.

CVE-2023-42893: an anonymous researcher

Maps

Available for: iPhone XS and later, iPad Pro 12.9-inch 2nd generation and later, iPad Pro 10.5-inch, iPad Pro 11-inch 1st generation and later, iPad Air 3rd generation and later, iPad 6th generation and later, and iPad mini 5th generation and later

Impact: An app may be able to read sensitive location information

Description: A path handling issue was addressed with improved validation.

CVE-2024-27810: LFY@secsys of Fudan University

MarketplaceKit

Available for: iPhone XS and later

Impact: A maliciously crafted webpage may be able to distribute a script that tracks users on other webpages

Description: A privacy issue was addressed with improved client ID handling for alternative app marketplaces.

CVE-2024-27852: Talal Haj Bakry and Tommy Mysk of Mysk Inc.

Notes

Available for: iPhone XS and later, iPad Pro 12.9-inch 2nd generation and later, iPad Pro 10.5-inch, iPad Pro 11-inch 1st generation and later, iPad Air 3rd generation and later, iPad 6th generation and later, and iPad mini 5th generation and later

Impact: An attacker with physical access to an iOS device may be able to access notes from the lock screen

Description: This issue was addressed through improved state management.

CVE-2024-27835: Andr.Ess

RemoteViewServices

Available for: iPhone XS and later, iPad Pro 12.9-inch 2nd generation and later, iPad Pro 10.5-inch, iPad Pro 11-inch 1st generation and later, iPad Air 3rd generation and later, iPad 6th generation and later, and iPad mini 5th generation and later

Impact: An attacker may be able to access user data

Description: A logic issue was addressed with improved checks.

CVE-2024-27816: Mickey Jin

Screenshots

Available for: iPhone XS and later, iPad Pro 12.9-inch 2nd generation and later, iPad Pro 10.5-inch, iPad Pro 11-inch 1st generation and later, iPad Air 3rd generation and later, iPad 6th generation and later, and iPad mini 5th generation and later

Impact: An attacker with physical access may be able to share items from the lock screen

Description: A permissions issue was addressed with improved validation.

CVE-2024-27803: an anonymous researcher

Shortcuts

Available for: iPhone XS and later, iPad Pro 12.9-inch 2nd generation and later, iPad Pro 10.5-inch, iPad Pro 11-inch 1st generation and later, iPad Air 3rd generation and later, iPad 6th generation and later, and iPad mini 5th generation and later

Impact: A shortcut may output sensitive user data without consent

Description: A path handling issue was addressed with improved validation.

CVE-2024-27821: Kirin, zbleet, and Csaba Fitzl of Kandji

Sync Services

Available for: iPhone XS and later, iPad Pro 12.9-inch 2nd generation and later, iPad Pro 10.5-inch, iPad Pro 11-inch 1st generation and later, iPad Air 3rd generation and later, iPad 6th generation and later, and iPad mini 5th generation and later

Impact: An app may be able to bypass Privacy preferences

Description: This issue was addressed with improved checks

CVE-2024-27847: Mickey Jin

Voice Control

Available for: iPhone XS and later, iPad Pro 12.9-inch 2nd generation and later, iPad Pro 10.5-inch, iPad Pro 11-inch 1st generation and later, iPad Air 3rd generation and later, iPad 6th generation and later, and iPad mini 5th generation and later

Impact: An attacker may be able to elevate privileges

Description: The issue was addressed with improved checks.

CVE-2024-27796: ajajfxhj

WebKit

Available for: iPhone XS and later, iPad Pro 12.9-inch 2nd generation and later, iPad Pro 10.5-inch, iPad Pro 11-inch 1st generation and later, iPad Air 3rd generation and later, iPad 6th generation and later, and iPad mini 5th generation and later

Impact: An attacker with arbitrary read and write capability may be able to bypass Pointer Authentication

Description: The issue was addressed with improved checks.

WebKit Bugzilla: 272750
CVE-2024-27834: Manfred Paul working with Trend Micro’s Zero Day Initiative


Additional recognition

App Store

We would like to acknowledge an anonymous researcher for their assistance.

CoreHAP

We would like to acknowledge Adrian Cable for their assistance.

Face ID

We would like to acknowledge Lucas Monteiro, Daniel Monteiro, and Felipe Monteiro for their assistance.

HearingCore

We would like to acknowledge an anonymous researcher for their assistance.

Managed Configuration

We would like to acknowledge 遥遥领先 for their assistance.

Safari Downloads

We would like to acknowledge Arsenii Kostromin (0x3c3e) for their assistance.

Status Bar

We would like to acknowledge Abhay Kailasia of Lakshmi Narain College of Technology Bhopal for their assistance.

Privacy & security improvements included in this update:

watchOS 10.5

Released May 13, 2024

AppleAVD

Available for: Apple Watch Series 4 and later

Impact: An app may be able to execute arbitrary code with kernel privileges

Description: The issue was addressed with improved memory handling.

CVE-2024-27804: Meysam Firouzi

AppleMobileFileIntegrity

Available for: Apple Watch Series 4 and later

Impact: An attacker may be able to access user data

Description: A logic issue was addressed with improved checks.

CVE-2024-27816: Mickey Jin

Maps

Available for: Apple Watch Series 4 and later

Impact: An app may be able to read sensitive location information

Description: A path handling issue was addressed with improved validation.

CVE-2024-27810: LFY@secsys of Fudan University

RemoteViewServices

Available for: Apple Watch Series 4 and later

Impact: An attacker may be able to access user data

Description: A logic issue was addressed with improved checks.

CVE-2024-27816: Mickey Jin

Shortcuts

Available for: Apple Watch Series 4 and later

Impact: A shortcut may output sensitive user data without consent

Description: A path handling issue was addressed with improved validation.

CVE-2024-27821: Kirin, zbleet, and Csaba Fitzl of Kandji

WebKit

Available for: Apple Watch Series 4 and later

Impact: An attacker with arbitrary read and write capability may be able to bypass Pointer Authentication

Description: The issue was addressed with improved checks.

WebKit Bugzilla: 272750
CVE-2024-27834: Manfred Paul working with Trend Micro’s Zero Day Initiative


Additional recognition

App Store

We would like to acknowledge an anonymous researcher for their assistance.

CoreHAP

We would like to acknowledge Adrian Cable for their assistance.

HearingCore

We would like to acknowledge an anonymous researcher for their assistance.

Managed Configuration

We would like to acknowledge 遥遥领先 for their assistance.

Privacy & security improvements included in this update:

macOS Sonoma 14.5

Released May 13, 2024

AppleAVD

Available for: macOS Sonoma

Impact: An app may be able to execute arbitrary code with kernel privileges

Description: The issue was addressed with improved memory handling.

CVE-2024-27804: Meysam Firouzi

AppleMobileFileIntegrity

Available for: macOS Sonoma

Impact: A local attacker may gain access to Keychain items

Description: A downgrade issue was addressed with additional code-signing restrictions.

CVE-2024-27837: Mickey Jin and ajajfxhj

AppleMobileFileIntegrity

Available for: macOS Sonoma

Impact: An attacker may be able to access user data

Description: A logic issue was addressed with improved checks.

CVE-2024-27816: Mickey Jin

AppleMobileFileIntegrity

Available for: macOS Sonoma

Impact: An app may be able to bypass certain Privacy preferences

Description: A downgrade issue affecting Intel-based Mac computers was addressed with additional code-signing restrictions.

CVE-2024-27825: Kirin

AppleVA

Available for: macOS Sonoma

Impact: Processing a file may lead to unexpected app termination or arbitrary code execution

Description: The issue was addressed with improved memory handling.

CVE-2024-27829: Amir Bazine and Karsten König of CrowdStrike Counter Adversary Operations, and Pwn2car working with Trend Micro’s Zero Day Initiative

AVEVideoEncoder

Available for: macOS Sonoma

Impact: An app may be able to disclose kernel memory

Description: The issue was addressed with improved memory handling.

CVE-2024-27841: an anonymous researcher

CFNetwork

Available for: macOS Sonoma

Impact: An app may be able to read arbitrary files

Description: A correctness issue was addressed with improved checks.

CVE-2024-23236: Ron Masas of Imperva

Finder

Available for: macOS Sonoma

Impact: An app may be able to read arbitrary files

Description: This issue was addressed through improved state management.

CVE-2024-27827: an anonymous researcher

Kernel

Available for: macOS Sonoma

Impact: An attacker may be able to cause unexpected app termination or arbitrary code execution

Description: The issue was addressed with improved memory handling.

CVE-2024-27818: pattern-f of Ant Security Light-Year Lab

Libsystem

Available for: macOS Sonoma

Impact: An app may be able to access protected user data

Description: A permissions issue was addressed by removing vulnerable code and adding additional checks.

CVE-2023-42893: an anonymous researcher

Maps

Available for: macOS Sonoma

Impact: An app may be able to read sensitive location information

Description: A path handling issue was addressed with improved validation.

CVE-2024-27810: LFY@secsys of Fudan University

PackageKit

Available for: macOS Sonoma

Impact: An app may be able to gain root privileges

Description: A logic issue was addressed with improved restrictions.

CVE-2024-27822: Scott Johnson, Mykola Grymalyuk of RIPEDA Consulting, Jordy Witteman, and Carlos Polop

PackageKit

Available for: macOS Sonoma

Impact: An app may be able to elevate privileges

Description: This issue was addressed by removing the vulnerable code.

CVE-2024-27824: Pedro Tôrres

PrintCenter

Available for: macOS Sonoma

Impact: An app may be able to execute arbitrary code out of its sandbox or with certain elevated privileges

Description: The issue was addressed with improved checks.

CVE-2024-27813: an anonymous researcher

RemoteViewServices

Available for: macOS Sonoma

Impact: An attacker may be able to access user data

Description: A logic issue was addressed with improved checks.

CVE-2024-27816: Mickey Jin

SharedFileList

Available for: macOS Sonoma

Impact: An app may be able to elevate privileges

Description: A logic issue was addressed with improved checks.

CVE-2024-27843: Mickey Jin

Shortcuts

Available for: macOS Sonoma

Impact: A shortcut may output sensitive user data without consent

Description: A path handling issue was addressed with improved validation.

CVE-2024-27821: Kirin, zbleet, and Csaba Fitzl of Kandji

StorageKit

Available for: macOS Sonoma

Impact: An attacker may be able to elevate privileges

Description: An authorization issue was addressed with improved state management.

CVE-2024-27798: Yann GASCUEL of Alter Solutions

Sync Services

Available for: macOS Sonoma

Impact: An app may be able to bypass Privacy preferences

Description: This issue was addressed with improved checks

CVE-2024-27847: Mickey Jin

udf

Available for: macOS Sonoma

Impact: An app may be able to execute arbitrary code with kernel privileges

Description: The issue was addressed with improved checks.

CVE-2024-27842: CertiK SkyFall Team

Voice Control

Available for: macOS Sonoma

Impact: An attacker may be able to elevate privileges

Description: The issue was addressed with improved checks.

CVE-2024-27796: ajajfxhj

WebKit

Available for: macOS Sonoma

Impact: An attacker with arbitrary read and write capability may be able to bypass Pointer Authentication

Description: The issue was addressed with improved checks.

WebKit Bugzilla: 272750
CVE-2024-27834: Manfred Paul working with Trend Micro’s Zero Day Initiative


Additional recognition

App Store

We would like to acknowledge an anonymous researcher for their assistance.

CoreHAP

We would like to acknowledge Adrian Cable for their assistance.

HearingCore

We would like to acknowledge an anonymous researcher for their assistance.

Managed Configuration

We would like to acknowledge 遥遥领先 for their assistance.

Music

We would like to acknowledge an anonymous researcher for their assistance.

PackageKit

We would like to acknowledge Mickey Jin for their assistance.

Safari Downloads

We would like to acknowledge Arsenii Kostromin (0x3c3e) for their assistance.

2 Likes

… as well as updates for tvOS, HomePod software and older versions of iOS, iPadOS and macOS.

1 Like

There is now also support for downloading apps directly from a developer’s website for EU users:

Apple has also allowed developers in the EU to make app installation possible from the web, in some circumstances.

(Apple releases iOS 17.5 with News+ games, Pride wallpaper, cross-platform tracking detection, more - 9to5Mac)

https://9to5mac.com/2024/03/12/iphone-app-store-changes-web-distribution-more/

1 Like