PT-2024-5374 · Webkit+1 · Webkit+1

Ryan Pickren

·

Published

2024-06-10

·

Updated

2024-07-03

·

CVE-2024-27812

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions visionOS versions prior to 1.2
Description The issue is related to an uncontrolled resource consumption in the WebKit component of the visionOS operating system. Exploitation of this issue may allow a remote attacker to inject arbitrary 3D objects and cause a denial-of-service. Processing web content may lead to a denial-of-service. The issue was addressed with improvements to the file handling protocol.
Recommendations For versions prior to 1.2, update to visionOS 1.2 to resolve the issue. As a temporary workaround, consider restricting the processing of web content to minimize the risk of exploitation.

Fix

Resource Exhaustion

Weakness Enumeration

Related Identifiers

BDU:2024-06007
CVE-2024-27812

Affected Products

Webkit
Visionos