CVE-2024-0258Patch(apple / ipad_os)

LOWCVSS 8.6 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch apple ipad_os systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

The issue was addressed with improved memory handling. This issue is fixed in iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4, tvOS 17.4, watchOS 10.4. An app may be able to execute arbitrary code out of its sandbox or with certain elevated privileges.

1.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-284

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • ipad_os
  • iphone_os
  • macos
  • tvos

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 1 signal
  • 2 total mentions across 1 day

Affected systems

Vendors
Products
ipad_osiphone_osmacostvoswatchos

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-06-18: 2Patch / Workaround · 2026-06-18: 2Technical Details · 2026-06-18: 106-18
Signal classification1 categories
Patch
2100.0%
Full discourse2 posts
  • Webtekno@webtekno
    Patch

    Ali Yabuz adlı Türk güvenlik araştırmacısı, Apple’ın iPhone, iPad, Mac, Apple Watch ve Apple TV gibi ürünlerini etkileyen kritik bir güvenlik açığı keşfetti. 📌 Apple tarafından doğrulanan ve CVE-2024-0258 olarak kayda geçen açık, uygulamaların korumalı alan dışına çıkıp rastgele kod çalıştırmasına yol açabilecek nitelikteydi. 📌 Apple, açığı kısa sürede yayımladığı güncellemelerle kapattı. 📌 Sorun; iOS 17.4, iPadOS 17.4, macOS Sonoma 14.4, tvOS 17.4 ve watchOS 10.4 sürümlerinde giderildi. Apple’ın güvenlik sayfasında Ali Yabuz’a araştırmacı olarak yer verildi.

    Post summary

    Apple quickly patched CVE-2024-0258 after its discovery by Ali Yabuz, fixing a critical code‑execution flaw across multiple iOS/Mac/watchOS/tvOS devices, with no evidence of active exploitation.

    12048717.4K
    511.0K followersView on X
  • Techno Wave@technowavecom
    Patch

    🚨 Türk güvenlik araştırmacısı Ali Yabuz, Apple cihazlarını etkileyen kritik bir açığı keşfetti. 📌 CVE-2024-0258 olarak kayda geçen açık; iPhone, iPad, Mac, Apple Watch ve Apple TV’yi etkiliyordu. 📌 Apple sorunu güncellemelerle kapattı ve araştırmacıyı resmi olarak teşekkür etti.

    Post summary

    The tweet reports that Turkish researcher Ali Yabuz identified the critical CVE‑2024‑0258 affecting various Apple devices, and Apple responded by releasing updates that closed the flaw.

    00000133
    562 followersView on X
CPE platform detail5 entries

5 of 5 entries

PartVendorProductVersionTarget SWTarget HW
OSappleipad_os---
OSappleiphone_os---
OSapplemacos---
OSappletvos---
OSapplewatchos---

Explore more