CVE-2024-54527

Published Dec 12, 2024

Last updated 2 months ago

Overview

Description
This issue was addressed with improved checks. This issue is fixed in watchOS 11.2, tvOS 18.2, macOS Sequoia 15.2, iOS 18.2 and iPadOS 18.2, macOS Ventura 13.7.2, macOS Sonoma 14.7.2. An app may be able to access sensitive user data.
Source
product-security@apple.com
NVD status
Modified

Risk scores

CVSS 3.1

Type
Primary
Base score
5.5
Impact score
3.6
Exploitability score
1.8
Vector string
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Severity
MEDIUM

Weaknesses

nvd@nist.gov
NVD-CWE-noinfo

Social media

Hype score
Not currently trending
  1. #exploit 1. macOS PackageKit Exploits https://t.co/REhVEuqtU6 2. CVE-2024-53704: SonicWall SSL VPN Session Hijacking https://t.co/JpSb5kZVnZ 3. CVE-2024-54527: MediaLibraryService Full TCC Bypass, Dive Deep into AMFI https://t.co/62vbuwlVrw

    @akaclandestine

    21 Feb 2025

    280 Impressions

    0 Retweets

    1 Like

    1 Bookmark

    0 Replies

    0 Quotes

  2. #exploit 1. macOS PackageKit Exploits https://t.co/zx4w5Y8Mrh 2. CVE-2024-53704: SonicWall SSL VPN Session Hijacking https://t.co/30mzp4qbep 3. CVE-2024-54527: MediaLibraryService Full TCC Bypass, Dive Deep into AMFI https://t.co/LkTNEQz3jx

    @ksg93rd

    17 Feb 2025

    239 Impressions

    2 Retweets

    5 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  3. #Vulnerability #Apple macOS Vulnerability CVE-2024-54527 Unveiled: TCC Bypass PoC Exploit Code Released https://t.co/4Azc3Z8KLQ

    @Komodosec

    13 Jan 2025

    35 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  4. Threat Alert: macOS Vulnerability CVE-2024-54527 Unveiled: TCC Bypass PoC Exploit Code Release CVE-2024-54527 Severity: ⚠️ Critical Maturity: 💢 Emerging Learn more: https://t.co/lFeDkrU0hz #CyberSecurity #ThreatIntel #InfoSec (1/3)

    @fletch_ai

    10 Jan 2025

    16 Impressions

    1 Retweet

    1 Like

    0 Bookmarks

    1 Reply

    0 Quotes

  5. macOSにおけるTCC迂回の脆弱性CVE-2024-54527に対応するPoC(攻撃の概念実証コード)が公開された。MediaLibraryService XPCサービスにおける欠陥。 https://t.co/dYdkjFwI3m

    @__kokumoto

    9 Jan 2025

    1088 Impressions

    2 Retweets

    12 Likes

    2 Bookmarks

    0 Replies

    0 Quotes

  6. A detailed technical and proof-of-concept (PoC) exploit code from security researcher Mickey Jin has unveiled a critical TCC (Transparency, Consent, and Control) bypass vulnerability in macOS, CVE-2024-54527. This vulnerability, affecting the MediaLibraryService XPC service,…

    @cybertzar

    9 Jan 2025

    57 Impressions

    0 Retweets

    2 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  7. macOS Vulnerability CVE-2024-54527 Unveiled: TCC Bypass PoC Exploit Code Released https://t.co/TJlQnNO2sK

    @Dinosn

    9 Jan 2025

    2294 Impressions

    10 Retweets

    29 Likes

    3 Bookmarks

    0 Replies

    0 Quotes

  8. macOS Vulnerability CVE-2024-54527 Unveiled: TCC Bypass #PoC Exploit Code Released Explore the details of the CVE-2024-54527 vulnerability in #macOS and understand how attackers can leverage powerful entitlements to bypass TCC protections https://t.co/sgKJVuy0qP

    @the_yellow_fall

    9 Jan 2025

    24 Impressions

    0 Retweets

    2 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

Configurations