PT-2024-4402 · Apple+2 · Visionos+7

Nick Galloway

·

Published

2024-02-19

·

Updated

2026-03-29

·

CVE-2024-1580

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions dav1d versions prior to 1.4.0 libdav1d-sys versions prior to 0.7.0 CoreMedia and WebRTC in Apple devices (affected versions not specified)
Description The issue is related to an integer overflow in the dav1d AV1 decoder that can occur when decoding videos with large frame sizes, leading to memory corruption within the AV1 decoder. This can allow a remote attacker to execute arbitrary code on affected devices. The vulnerability affects various Apple devices, including those running iOS, iPadOS, visionOS, and macOS, as well as the Safari browser and Fedora.
Recommendations For dav1d versions prior to 1.4.0, upgrade past version 1.4.0. For libdav1d-sys versions prior to 0.7.0, upgrade to version 0.7.0, which includes dav1d 1.4.0. For CoreMedia and WebRTC in Apple devices, apply the latest security updates released by Apple to address the vulnerability. As a temporary workaround, consider restricting the use of the dav1d AV1 decoder until a patch is available.

Fix

Integer Overflow

Weakness Enumeration

Related Identifiers

BDU:2024-04901
CVE-2024-1580
DSA-5686-1
GHSA-MC39-H54G-PVW6
MGASA-2024-0111
OESA-2025-2614
OPENSUSE-SU-2024:13703-1
RUSTSEC-2024-0016
SUSE-SU-2024:0963-1
SUSE-SU-2024:0964-1
SUSE-SU-2024_0963-1
SUSE-SU-2024_0964-1

Affected Products

Astra Linux
Coremedia
Apple Macos
Safari
Suse
Ios
Ipados
Visionos