CVE-2024-54529 is a logic issue affecting Apple macOS (Sequoia, Ventura, and Sonoma) that could allow an application to execute arbitrary code with kernel privileges. This high-severity vulnerability (CVSS 7.8) requires user interaction (UI:R) and local access (AV:L) to achieve high impact on confidentiality, integrity, and availability. While not currently in CISA's KEV catalog and lacking public exploit code in common frameworks, Project Zero has published an article detailing its exploitation, indicating a higher level of community and media attention than most CVEs.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 13.0, < 13.7.2CPE matchmatch criteria | cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:* | ||
>= 14.0, < 14.7.2CPE matchmatch criteria | cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:* | ||
>= 15.0, < 15.2CPE matchmatch criteria | cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:* | ||
>= 0, < 13.7.2CPE match | cpe:2.3:a:apple:macos:*:*:*:*:*:*:*:* | ||
>= 0, < 14.7.2CPE match | cpe:2.3:a:apple:macos:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.