CVE-2024-54529PoC(apple / macos)

MEDIUMCVSS 7.8 · HIGH

Exploit discussion active in current signal (8 latest mentions)

Immediate actions

  • Patch apple macos systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

A logic issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.2, macOS Sonoma 14.7.2, macOS Ventura 13.7.2. An app may be able to execute arbitrary code out of its sandbox or with certain elevated privileges.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-94

Priority

MEDIUM

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

RISING

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • macos

Threat summary

  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 16 mentions across 6 observed days
  • Momentum state: rising

What's happening

  • Exploit tool or code specified in 4 signals
  • PoC mentioned or linked in 10 signals
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 10 signals
  • General: 4 classified signals
  • Peaked at 8 mentions on most recent observed day (2026-08-08)
  • 16 total mentions across 6 days

Affected systems

Vendors
Products
macos

Deep dive

Activity timeline16 mentions / 6d
02468Mentions · 2026-01-30: 2Mentions · 2026-01-31: 1Mentions · 2026-03-04: 1Mentions · 2026-03-22: 1Mentions · 2026-04-15: 3Mentions · 2026-08-08: 8PoC Mentioned / Linked · 2026-01-30: 2PoC Mentioned / Linked · 2026-08-08: 8Exploit Tool / Code · 2026-01-30: 1Exploit Tool / Code · 2026-08-08: 3Patch / Workaround · 2026-01-30: 1Technical Details · 2026-01-30: 1Technical Details · 2026-04-15: 1Technical Details · 2026-08-08: 801-3001-3103-0403-2204-1508-08
Signal classification4 categories
PoC
743.8%
General
425.0%
Exploit
318.8%
Disclosure
212.5%
Referenced assets8 URLs
Classification over time
DateTotalLabels
2026-01-302
PoC2
2026-01-311
General1
2026-03-041
Disclosure1
2026-03-221
General1
2026-04-153
Disclosure1General2
2026-08-088
Exploit3PoC5
Full discourse16 posts
  • Dillon Franke@dillon_franke
    PoC

    It's been just over a year since CVE-2024-54529 was patched. To celebrate, I'm open-sourcing my full PoC exploit for this CoreAudio type confusion vulnerability 🔊 The code is right here! Enjoy: https://github.com/googleprojectzero/p0tools/tree/master/CoreAudioFuzz/exploit https://t.co/1tu0qyHsQg

    Post summary

    The author announces the open‑source release of a proof‑of‑concept exploit for CVE‑2024‑54529, a CoreAudio type‑confusion flaw that was patched over a year ago, with a link to the code on GitHub.

    580136119037.5K
    1.8K followersView on X
  • Project Zero Bugs@ProjectZeroBugs
    PoC

    Breaking the Sound Barrier, Part II: Exploiting CVE-2024-54529 https://projectzero.google/2026/01/sound-barrier-2.html

    Post summary

    Project Zero publishes a write‑up on CVE‑2024‑54529, indicating a proof‑of‑concept exploit is available.

    115066275.4K
    36.1K followersView on X
  • Anas@Naz_style
    Disclosure

    @khanhduytran0 CVE that might be useful for IOS 18 JB Kernel CVE-2024-54518 CVE-2024-54522 CVE-2024-54523 Sandbox/ Privilege CVE-2024-54468 CVE-2024-54529 CVE-2024-54535 WebKit CVE-2024-54543 CVE-2025-14174 CVE-2025-43529 CVE-2025-43300

    Post summary

    The tweet lists several CVE identifiers that may be useful for an iOS 18 jailbreak, but provides no further technical or contextual information.

    010134902
    75 followersView on X
  • Cyber Research@Cyb3rR3s34rch
    Exploit

    Google Project Zero published a full exploit write-up for CVE-2024-54529, a type confusion in macOS CoreAudio’s coreaudiod that they turned from a crash into a working exploit. https://cyberresearch.us/li

    Post summary

    Google Project Zero released a detailed exploit write‑up that transforms a type‑confusion crash in macOS CoreAudio’s coreaudiod into a functional exploit.

    1000032
    69 followersView on X
  • Cyber Research@Cyb3rR3s34rch
    PoC

    Google Project Zero detailed how CVE-2024-54529 in macOS coreaudiod goes from a type-confusion crash to a working exploit. https://cyberresearch.us/li

    Post summary

    Google Project Zero released a working exploit for CVE‑2024‑54529, a type‑confusion flaw in macOS coreaudiod, and shared detailed analysis via an external link.

    0000043
    69 followersView on X
  • Cyber Research@Cyb3rR3s34rch
    PoC

    Google Project Zero detailed exploitation of CVE-2024-54529, a type confusion in macOS coreaudiod’s CoreAudio Mach service that can be turned from a crash into a working exploit. https://cyberresearch.us/li

    Post summary

    Google Project Zero has published detailed proof‑of‑concept details for CVE‑2024‑54529, a type‑confusion flaw in macOS coreaudiod that can be exploited in the wild.

    0000046
    69 followersView on X
  • Cyber Research@Cyb3rR3s34rch
    PoC

    Google Project Zero published a full exploit walkthrough for CVE-2024-54529, a type confusion in macOS coreaudiod reached via the CoreAudio Mach service. https://cyberresearch.us/li

    Post summary

    Google Project Zero released a detailed proof‑of‑concept walkthrough for CVE‑2024‑54529, a type confusion in macOS coreaudiod, but no evidence of active exploitation or patches is mentioned.

    0000040
    69 followersView on X
  • Cyber Research@Cyb3rR3s34rch
    Exploit

    Google Project Zero turned CVE-2024-54529—a type confusion in macOS coreaudiod—from a crash into a working exploit, underscoring risk in a privileged system audio daemon. https://cyberresearch.us/li

    Post summary

    Google Project Zero demonstrated a functional exploit for CVE-2024-54529, a type‑confusion vulnerability in macOS coreaudiod, underscoring the seriousness of the privileged system audio daemon flaw.

    0000040
    69 followersView on X
  • Cyber Research@Cyb3rR3s34rch
    PoC

    Google Project Zero detailed a full exploit path for CVE-2024-54529, a type confusion in macOS coreaudiod’s CoreAudio Mach service that turns a crash into a working local exploit. https://cyberresearch.us/li

    Post summary

    Google Project Zero has released a detailed proof‑of‑concept for CVE-2024-54529, showing a type‑confusion flaw in macOS coreaudiod that escalates a crash into a local exploit.

    0000037
    69 followersView on X
  • Cyber Research@Cyb3rR3s34rch
    PoC

    Google Project Zero published a full exploit walkthrough for CVE-2024-54529, a type confusion bug in macOS coreaudiod reached over Mach IPC. https://cyberresearch.us/li

    Post summary

    Google Project Zero published a comprehensive proof‑of‑concept walkthrough for CVE‑2024‑54529, detailing a type‑confusion flaw in macOS coreaudiod accessed over Mach IPC.

    0000037
    69 followersView on X
  • Cyber Research@Cyb3rR3s34rch
    Exploit

    Project Zero detailed a working exploit for CVE-2024-54529, a type confusion in macOS coreaudiod’s CoreAudio Mach path—local attack surface that turned a crash into reliable code abuse. https://cyberresearch.us/li

    Post summary

    Project Zero has published a working exploit for CVE-2024-54529, a type‑confusion in macOS coreaudiod that turns a crash into reliable code execution, but no evidence of active exploitation or available patches is provided.

    0000042
    69 followersView on X
  • Security Arsenal, LLC@SecurityAr58409
    Disclosure

    🔒 #CyberSecurity CVE-2024-54529: macOS Coreaudiod Type Confusion Exploitation – Detection and Ha… "Google Project Zero's latest research, "Breaking the Sound Barrier, Part II,"…" 🔗 https://securityarsenal.com/blog/cve-2024-54529-macos-coreaudiod-type-confusion-exploitation-detection-and-hardening #CyberSecurity #ThreatIntel #sigmarule #kqldetection #threathunting

    Post summary

    The post announces a newly identified macOS Coreaudiod type‑confusion vulnerability (CVE‑2024‑54529) and links to a blog that discusses detection and hardening measures, but it does not provide exploit code or patch information.

    0000045
    10 followersView on X
  • Security Arsenal, LLC@SecurityAr58409
    General

    🔒 #CyberSecurity Defending Against CVE-2024-54529: The macOS coreaudiod Type Confusion Vulnerabi… "Cybersecurity researchers at Google Project Zero have recently provided an in-depth…" 🔗 https://securityarsenal.com/blog/defending-against-cve-2024-54529-the-macos-coreaudiod-type-confusion-vulnerability #CyberSecurity #ThreatIntel #vulnerability #cve #patch

    Post summary

    The tweet references CVE‑2024‑54529 and links to a blog post about defending against it, but provides no concrete technical details, PoC, exploit code, evidence of active use, or patch information.

    0000027
    10 followersView on X
  • Security Arsenal, LLC@SecurityAr58409
    General

    🔒 #CyberSecurity Defending Against CVE-2024-54529: Protecting macOS from Core Audio Exploits "Recent research from Google Project Zero has shed light on a significant security flaw within…" 🔗 https://securityarsenal.com/blog/defending-against-cve-2024-54529-protecting-macos-from-core-audio-exploits #CyberSecurity #ThreatIntel #vulnerability #cve #patch

    Post summary

    The tweet announces awareness of CVE-2024-54529 in macOS Core Audio but provides no technical details, PoC, or evidence of active exploitation.

    0000030
    10 followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    General

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: Breaking the Sound Barrier, Part II: Exploiting CVE-2024-54529 Intel Report: https://ift.tt/aDRpQWe

    Post summary

    Alert for CVE-2024-54529 with a report link; no evidence of PoC, exploit code, active exploitation, patch, or technical details.

    0000034
    291 followersView on X
  • VulnTracker@vuln_tracker
    General

    @ProjectZeroBugs You now can see the full details about CVE-2024-54529 from http://Vulntracker.io !

    Post summary

    The tweet only directs readers to a link for more information on CVE-2024-54529, without providing any additional details or evidence of exploitation.

    00000157
    335 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
OSapplemacos---

Explore more