CVE-2024-40799
Description
An out-of-bounds read in multiple Apple operating systems could let a maliciously crafted file terminate the app.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
An out-of-bounds read in multiple Apple operating systems could let a maliciously crafted file terminate the app.
Vulnerability
CVE-2024-40799 is an out-of-bounds read vulnerability in Apple's core processing of files. The root cause is insufficient input validation, which can be triggered when the system handles a maliciously crafted file [1]. This issue affects a wide range of Apple platforms, including iOS, iPadOS, macOS, tvOS, visionOS, and watchOS [1][2].
Exploitation
To exploit this vulnerability, an attacker would need to deliver a specially crafted file to a user's device. The file could be delivered through various means, such as email, a website, or direct file transfer. No special permissions beyond normal file access are required for the application that processes the file. The out-of-bounds read occurs during file parsing, leading to unpredictable behavior [1][2].
Impact
The primary impact of successfully exploiting this vulnerability is unexpected app termination. This constitutes a denial-of-service (DoS) condition, potentially disrupting user productivity or causing data loss if the application was in the middle of an operation. There is no indication that this bug leads to arbitrary code execution or data exposure based on the available information [1][2].
Mitigation
Apple has addressed this issue in the following software releases: iOS 16.7.9 and iPadOS 16.7.9, iOS 17.6 and iPadOS 17.6, macOS Monterey 12.7.6, macOS Sonoma 14.6, macOS Ventura 13.6.8, tvOS 17.6, visionOS 1.3, and watchOS 10.6 [1][2][4]. Users are strongly advised to update to these latest versions to protect against potential exploitation.
AI Insight generated on May 20, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
9cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*range: <12.7.6
- (no CPE)range: <12.7.6 >=12 <=12.7.6; <13.6.8 >=13 <=13.6.8; <14.6 >=14 <=14.6
cpe:2.3:o:apple:tvos:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:o:apple:tvos:*:*:*:*:*:*:*:*range: <17.6
- (no CPE)range: <17.6
- Range: <16.7.9 >=16 <=16.7.9; <17.6 >=17 <=17.6
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
31- seclists.org/fulldisclosure/2024/Jul/16nvdMailing ListThird Party Advisory
- seclists.org/fulldisclosure/2024/Jul/17nvdMailing ListThird Party Advisory
- seclists.org/fulldisclosure/2024/Jul/18nvdMailing ListThird Party Advisory
- seclists.org/fulldisclosure/2024/Jul/19nvdMailing ListThird Party Advisory
- seclists.org/fulldisclosure/2024/Jul/20nvdMailing ListThird Party Advisory
- seclists.org/fulldisclosure/2024/Jul/21nvdMailing ListThird Party Advisory
- seclists.org/fulldisclosure/2024/Jul/22nvdMailing ListThird Party Advisory
- seclists.org/fulldisclosure/2024/Jul/23nvdMailing ListThird Party Advisory
- support.apple.com/en-us/HT214116nvdRelease NotesVendor Advisory
- support.apple.com/en-us/HT214117nvdRelease NotesVendor Advisory
- support.apple.com/en-us/HT214118nvdRelease NotesVendor Advisory
- support.apple.com/en-us/HT214119nvdRelease NotesVendor Advisory
- support.apple.com/en-us/HT214120nvdRelease NotesVendor Advisory
- support.apple.com/en-us/HT214122nvdRelease NotesVendor Advisory
- support.apple.com/en-us/HT214123nvdRelease NotesVendor Advisory
- support.apple.com/en-us/HT214124nvdRelease NotesVendor Advisory
- support.apple.com/en-us/120908nvd
- support.apple.com/en-us/120909nvd
- support.apple.com/en-us/120910nvd
- support.apple.com/en-us/120911nvd
- support.apple.com/en-us/120912nvd
- support.apple.com/en-us/120914nvd
- support.apple.com/en-us/120915nvd
- support.apple.com/en-us/120916nvd
- support.apple.com/kb/HT214116nvd
- support.apple.com/kb/HT214117nvd
- support.apple.com/kb/HT214118nvd
- support.apple.com/kb/HT214119nvd
- support.apple.com/kb/HT214120nvd
- support.apple.com/kb/HT214122nvd
- support.apple.com/kb/HT214124nvd
News mentions
0No linked articles in our index yet.