iOS 17.5 release notes
(…)
Tracking Notifications
Cross-Platform Tracking Detection delivers notifications to users if a compatible Bluetooth tracker they do not own is moving with them, regardless of what operating system the device is paired with
Other software updates released today out-of-beta include the following:
watchOS 10.5 HomePod 17.5 tvOS 17.5 macOS 14.5 macOS 13.6.7HomePod users can expect “performance and stability improvements,” according to release notes. macOS focuses on security updates.
Privacy & security improvements included in these updates:
AppleAVD
Available for: iPhone XS and later, iPad Pro 12.9-inch 2nd generation and later, iPad Pro 10.5-inch, iPad Pro 11-inch 1st generation and later, iPad Air 3rd generation and later, iPad 6th generation and later, and iPad mini 5th generation and later
Impact: An app may be able to execute arbitrary code with kernel privileges
Description: The issue was addressed with improved memory handling.
CVE-2024-27804: Meysam Firouzi
AppleMobileFileIntegrity
Available for: iPhone XS and later, iPad Pro 12.9-inch 2nd generation and later, iPad Pro 10.5-inch, iPad Pro 11-inch 1st generation and later, iPad Air 3rd generation and later, iPad 6th generation and later, and iPad mini 5th generation and later
Impact: An attacker may be able to access user data
Description: A logic issue was addressed with improved checks.
CVE-2024-27816: Mickey Jin
AVEVideoEncoder
Available for: iPhone XS and later, iPad Pro 12.9-inch 2nd generation and later, iPad Pro 10.5-inch, iPad Pro 11-inch 1st generation and later, iPad Air 3rd generation and later, iPad 6th generation and later, and iPad mini 5th generation and later
Impact: An app may be able to disclose kernel memory
Description: The issue was addressed with improved memory handling.
CVE-2024-27841: an anonymous researcher
Find My
Available for: iPhone XS and later, iPad Pro 12.9-inch 2nd generation and later, iPad Pro 10.5-inch, iPad Pro 11-inch 1st generation and later, iPad Air 3rd generation and later, iPad 6th generation and later, and iPad mini 5th generation and later
Impact: A malicious application may be able to determine a user’s current location
Description: A privacy issue was addressed by moving sensitive data to a more secure location.
CVE-2024-27839: Alexander Heinrich, SEEMOO, TU Darmstadt, and Shai Mishali
Kernel
Available for: iPhone XS and later, iPad Pro 12.9-inch 2nd generation and later, iPad Pro 10.5-inch, iPad Pro 11-inch 1st generation and later, iPad Air 3rd generation and later, iPad 6th generation and later, and iPad mini 5th generation and later
Impact: An attacker may be able to cause unexpected app termination or arbitrary code execution
Description: The issue was addressed with improved memory handling.
CVE-2024-27818: pattern-f of Ant Security Light-Year Lab
Libsystem
Available for: iPhone XS and later, iPad Pro 12.9-inch 2nd generation and later, iPad Pro 10.5-inch, iPad Pro 11-inch 1st generation and later, iPad Air 3rd generation and later, iPad 6th generation and later, and iPad mini 5th generation and later
Impact: An app may be able to access protected user data
Description: A permissions issue was addressed by removing vulnerable code and adding additional checks.
CVE-2023-42893: an anonymous researcher
Maps
Available for: iPhone XS and later, iPad Pro 12.9-inch 2nd generation and later, iPad Pro 10.5-inch, iPad Pro 11-inch 1st generation and later, iPad Air 3rd generation and later, iPad 6th generation and later, and iPad mini 5th generation and later
Impact: An app may be able to read sensitive location information
Description: A path handling issue was addressed with improved validation.
CVE-2024-27810: LFY@secsys of Fudan University
MarketplaceKit
Available for: iPhone XS and later
Impact: A maliciously crafted webpage may be able to distribute a script that tracks users on other webpages
Description: A privacy issue was addressed with improved client ID handling for alternative app marketplaces.
CVE-2024-27852: Talal Haj Bakry and Tommy Mysk of Mysk Inc.
Notes
Available for: iPhone XS and later, iPad Pro 12.9-inch 2nd generation and later, iPad Pro 10.5-inch, iPad Pro 11-inch 1st generation and later, iPad Air 3rd generation and later, iPad 6th generation and later, and iPad mini 5th generation and later
Impact: An attacker with physical access to an iOS device may be able to access notes from the lock screen
Description: This issue was addressed through improved state management.
CVE-2024-27835: Andr.Ess
RemoteViewServices
Available for: iPhone XS and later, iPad Pro 12.9-inch 2nd generation and later, iPad Pro 10.5-inch, iPad Pro 11-inch 1st generation and later, iPad Air 3rd generation and later, iPad 6th generation and later, and iPad mini 5th generation and later
Impact: An attacker may be able to access user data
Description: A logic issue was addressed with improved checks.
CVE-2024-27816: Mickey Jin
Screenshots
Available for: iPhone XS and later, iPad Pro 12.9-inch 2nd generation and later, iPad Pro 10.5-inch, iPad Pro 11-inch 1st generation and later, iPad Air 3rd generation and later, iPad 6th generation and later, and iPad mini 5th generation and later
Impact: An attacker with physical access may be able to share items from the lock screen
Description: A permissions issue was addressed with improved validation.
CVE-2024-27803: an anonymous researcher
Shortcuts
Available for: iPhone XS and later, iPad Pro 12.9-inch 2nd generation and later, iPad Pro 10.5-inch, iPad Pro 11-inch 1st generation and later, iPad Air 3rd generation and later, iPad 6th generation and later, and iPad mini 5th generation and later
Impact: A shortcut may output sensitive user data without consent
Description: A path handling issue was addressed with improved validation.
CVE-2024-27821: Kirin, zbleet, and Csaba Fitzl of Kandji
Sync Services
Available for: iPhone XS and later, iPad Pro 12.9-inch 2nd generation and later, iPad Pro 10.5-inch, iPad Pro 11-inch 1st generation and later, iPad Air 3rd generation and later, iPad 6th generation and later, and iPad mini 5th generation and later
Impact: An app may be able to bypass Privacy preferences
Description: This issue was addressed with improved checks
CVE-2024-27847: Mickey Jin
Voice Control
Available for: iPhone XS and later, iPad Pro 12.9-inch 2nd generation and later, iPad Pro 10.5-inch, iPad Pro 11-inch 1st generation and later, iPad Air 3rd generation and later, iPad 6th generation and later, and iPad mini 5th generation and later
Impact: An attacker may be able to elevate privileges
Description: The issue was addressed with improved checks.
CVE-2024-27796: ajajfxhj
WebKit
Available for: iPhone XS and later, iPad Pro 12.9-inch 2nd generation and later, iPad Pro 10.5-inch, iPad Pro 11-inch 1st generation and later, iPad Air 3rd generation and later, iPad 6th generation and later, and iPad mini 5th generation and later
Impact: An attacker with arbitrary read and write capability may be able to bypass Pointer Authentication
Description: The issue was addressed with improved checks.
WebKit Bugzilla: 272750
CVE-2024-27834: Manfred Paul working with Trend Micro’s Zero Day Initiative
Additional recognition
App Store
We would like to acknowledge an anonymous researcher for their assistance.
CoreHAP
We would like to acknowledge Adrian Cable for their assistance.
Face ID
We would like to acknowledge Lucas Monteiro, Daniel Monteiro, and Felipe Monteiro for their assistance.
HearingCore
We would like to acknowledge an anonymous researcher for their assistance.
Managed Configuration
We would like to acknowledge 遥遥领先 for their assistance.
Safari Downloads
We would like to acknowledge Arsenii Kostromin (0x3c3e) for their assistance.
Status Bar
We would like to acknowledge Abhay Kailasia of Lakshmi Narain College of Technology Bhopal for their assistance.
Privacy & security improvements included in this update:
watchOS 10.5
Released May 13, 2024
AppleAVD
Available for: Apple Watch Series 4 and later
Impact: An app may be able to execute arbitrary code with kernel privileges
Description: The issue was addressed with improved memory handling.
CVE-2024-27804: Meysam Firouzi
AppleMobileFileIntegrity
Available for: Apple Watch Series 4 and later
Impact: An attacker may be able to access user data
Description: A logic issue was addressed with improved checks.
CVE-2024-27816: Mickey Jin
Maps
Available for: Apple Watch Series 4 and later
Impact: An app may be able to read sensitive location information
Description: A path handling issue was addressed with improved validation.
CVE-2024-27810: LFY@secsys of Fudan University
RemoteViewServices
Available for: Apple Watch Series 4 and later
Impact: An attacker may be able to access user data
Description: A logic issue was addressed with improved checks.
CVE-2024-27816: Mickey Jin
Shortcuts
Available for: Apple Watch Series 4 and later
Impact: A shortcut may output sensitive user data without consent
Description: A path handling issue was addressed with improved validation.
CVE-2024-27821: Kirin, zbleet, and Csaba Fitzl of Kandji
WebKit
Available for: Apple Watch Series 4 and later
Impact: An attacker with arbitrary read and write capability may be able to bypass Pointer Authentication
Description: The issue was addressed with improved checks.
WebKit Bugzilla: 272750
CVE-2024-27834: Manfred Paul working with Trend Micro’s Zero Day Initiative
Additional recognition
App Store
We would like to acknowledge an anonymous researcher for their assistance.
CoreHAP
We would like to acknowledge Adrian Cable for their assistance.
HearingCore
We would like to acknowledge an anonymous researcher for their assistance.
Managed Configuration
We would like to acknowledge 遥遥领先 for their assistance.
Privacy & security improvements included in this update:
macOS Sonoma 14.5
Released May 13, 2024
AppleAVD
Available for: macOS Sonoma
Impact: An app may be able to execute arbitrary code with kernel privileges
Description: The issue was addressed with improved memory handling.
CVE-2024-27804: Meysam Firouzi
AppleMobileFileIntegrity
Available for: macOS Sonoma
Impact: A local attacker may gain access to Keychain items
Description: A downgrade issue was addressed with additional code-signing restrictions.
CVE-2024-27837: Mickey Jin and ajajfxhj
AppleMobileFileIntegrity
Available for: macOS Sonoma
Impact: An attacker may be able to access user data
Description: A logic issue was addressed with improved checks.
CVE-2024-27816: Mickey Jin
AppleMobileFileIntegrity
Available for: macOS Sonoma
Impact: An app may be able to bypass certain Privacy preferences
Description: A downgrade issue affecting Intel-based Mac computers was addressed with additional code-signing restrictions.
CVE-2024-27825: Kirin
AppleVA
Available for: macOS Sonoma
Impact: Processing a file may lead to unexpected app termination or arbitrary code execution
Description: The issue was addressed with improved memory handling.
CVE-2024-27829: Amir Bazine and Karsten König of CrowdStrike Counter Adversary Operations, and Pwn2car working with Trend Micro’s Zero Day Initiative
AVEVideoEncoder
Available for: macOS Sonoma
Impact: An app may be able to disclose kernel memory
Description: The issue was addressed with improved memory handling.
CVE-2024-27841: an anonymous researcher
CFNetwork
Available for: macOS Sonoma
Impact: An app may be able to read arbitrary files
Description: A correctness issue was addressed with improved checks.
CVE-2024-23236: Ron Masas of Imperva
Finder
Available for: macOS Sonoma
Impact: An app may be able to read arbitrary files
Description: This issue was addressed through improved state management.
CVE-2024-27827: an anonymous researcher
Kernel
Available for: macOS Sonoma
Impact: An attacker may be able to cause unexpected app termination or arbitrary code execution
Description: The issue was addressed with improved memory handling.
CVE-2024-27818: pattern-f of Ant Security Light-Year Lab
Libsystem
Available for: macOS Sonoma
Impact: An app may be able to access protected user data
Description: A permissions issue was addressed by removing vulnerable code and adding additional checks.
CVE-2023-42893: an anonymous researcher
Maps
Available for: macOS Sonoma
Impact: An app may be able to read sensitive location information
Description: A path handling issue was addressed with improved validation.
CVE-2024-27810: LFY@secsys of Fudan University
PackageKit
Available for: macOS Sonoma
Impact: An app may be able to gain root privileges
Description: A logic issue was addressed with improved restrictions.
CVE-2024-27822: Scott Johnson, Mykola Grymalyuk of RIPEDA Consulting, Jordy Witteman, and Carlos Polop
PackageKit
Available for: macOS Sonoma
Impact: An app may be able to elevate privileges
Description: This issue was addressed by removing the vulnerable code.
CVE-2024-27824: Pedro Tôrres
PrintCenter
Available for: macOS Sonoma
Impact: An app may be able to execute arbitrary code out of its sandbox or with certain elevated privileges
Description: The issue was addressed with improved checks.
CVE-2024-27813: an anonymous researcher
RemoteViewServices
Available for: macOS Sonoma
Impact: An attacker may be able to access user data
Description: A logic issue was addressed with improved checks.
CVE-2024-27816: Mickey Jin
SharedFileList
Available for: macOS Sonoma
Impact: An app may be able to elevate privileges
Description: A logic issue was addressed with improved checks.
CVE-2024-27843: Mickey Jin
Shortcuts
Available for: macOS Sonoma
Impact: A shortcut may output sensitive user data without consent
Description: A path handling issue was addressed with improved validation.
CVE-2024-27821: Kirin, zbleet, and Csaba Fitzl of Kandji
StorageKit
Available for: macOS Sonoma
Impact: An attacker may be able to elevate privileges
Description: An authorization issue was addressed with improved state management.
CVE-2024-27798: Yann GASCUEL of Alter Solutions
Sync Services
Available for: macOS Sonoma
Impact: An app may be able to bypass Privacy preferences
Description: This issue was addressed with improved checks
CVE-2024-27847: Mickey Jin
udf
Available for: macOS Sonoma
Impact: An app may be able to execute arbitrary code with kernel privileges
Description: The issue was addressed with improved checks.
CVE-2024-27842: CertiK SkyFall Team
Voice Control
Available for: macOS Sonoma
Impact: An attacker may be able to elevate privileges
Description: The issue was addressed with improved checks.
CVE-2024-27796: ajajfxhj
WebKit
Available for: macOS Sonoma
Impact: An attacker with arbitrary read and write capability may be able to bypass Pointer Authentication
Description: The issue was addressed with improved checks.
WebKit Bugzilla: 272750
CVE-2024-27834: Manfred Paul working with Trend Micro’s Zero Day Initiative
Additional recognition
App Store
We would like to acknowledge an anonymous researcher for their assistance.
CoreHAP
We would like to acknowledge Adrian Cable for their assistance.
HearingCore
We would like to acknowledge an anonymous researcher for their assistance.
Managed Configuration
We would like to acknowledge 遥遥领先 for their assistance.
Music
We would like to acknowledge an anonymous researcher for their assistance.
PackageKit
We would like to acknowledge Mickey Jin for their assistance.
Safari Downloads
We would like to acknowledge Arsenii Kostromin (0x3c3e) for their assistance.
