PT-2024-19794 · Apple · Garageband
Marc Schoenefeld
·
Published
2024-03-12
·
Updated
2024-12-09
·
CVE-2024-23300
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
GarageBand versions prior to 10.4.11
Description
A use-after-free issue was addressed with improved memory management. Processing a maliciously crafted file may lead to unexpected app termination or arbitrary code execution. This issue affects macOS Sonoma and Ventura users.
Recommendations
For GarageBand versions prior to 10.4.11, update to version 10.4.11 to resolve the issue. As a temporary workaround, consider avoiding the processing of maliciously crafted files until the update is applied.
Fix
Use After Free
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Garageband