PT-2024-5374 · Webkit+1 · Webkit+1
Ryan Pickren
·
Published
2024-06-10
·
Updated
2024-07-03
·
CVE-2024-27812
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
visionOS versions prior to 1.2
Description
The issue is related to an uncontrolled resource consumption in the WebKit component of the visionOS operating system. Exploitation of this issue may allow a remote attacker to inject arbitrary 3D objects and cause a denial-of-service. Processing web content may lead to a denial-of-service. The issue was addressed with improvements to the file handling protocol.
Recommendations
For versions prior to 1.2, update to visionOS 1.2 to resolve the issue. As a temporary workaround, consider restricting the processing of web content to minimize the risk of exploitation.
Fix
Resource Exhaustion
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Webkit
Visionos