PT-2025-3049 · Apple · Music

Dominik Penner

+1

·

Published

2025-01-15

·

Updated

2025-01-16

·

CVE-2024-54540

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Apple Music versions prior to 1.5.0.152
Description The issue was addressed with improved input sanitization. Processing maliciously crafted web content may disclose internal states of the app.
Recommendations For versions prior to 1.5.0.152, update to Apple Music 1.5.0.152 for Windows to resolve the issue. As a temporary workaround, consider avoiding the processing of web content from untrusted sources until the update is applied.

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2024-54540

Affected Products

Music