CVE-2024-54486
Description
The issue was addressed with improved checks. This issue is fixed in iOS 18.2 and iPadOS 18.2, iPadOS 17.7.3, macOS Sequoia 15.2, macOS Sonoma 14.7.2, macOS Ventura 13.7.2, tvOS 18.2, visionOS 2.2, watchOS 11.2. Processing a maliciously crafted font may result in the disclosure of process memory.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Processing a maliciously crafted font can disclose process memory; Apple fixed it in multiple OS updates.
CVE-2024-54486 is a memory disclosure vulnerability in Apple's font parsing engine. The issue stems from insufficient validation when processing crafted font files, allowing an attacker to read portions of process memory that may contain sensitive data.
Exploitation requires the victim to process a malicious font, which can occur through web content, email attachments, or document previews. No special privileges or user interaction beyond normal usage is needed, making it a remotely triggerable information leak.
A successful attack could expose kernel or application memory, potentially leaking credentials, encryption keys, or other confidential information. The CVSS v3 base score of 6.5 reflects the medium severity due to the need for user interaction and the confidentiality impact.
Apple addressed the vulnerability with improved checks in iOS 18.2, iPadOS 18.2, iPadOS 17.7.3, macOS Sequoia 15.2, macOS Sonoma 14.7.2, macOS Ventura 13.7.2, tvOS 18.2, visionOS 2.2, and watchOS 11.2 [1][2][3][4]. Users are advised to update their devices to the latest available versions.
AI Insight generated on May 20, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
9cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*range: <17.7.3
- (no CPE)range: <18.2, <17.7.3
cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*range: <13.7.2
- (no CPE)range: <15.2, <14.7.2, <13.7.2
- Range: <18.2
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
13- support.apple.com/en-us/121837nvdVendor Advisory
- support.apple.com/en-us/121838nvdVendor Advisory
- support.apple.com/en-us/121839nvdVendor Advisory
- support.apple.com/en-us/121840nvdVendor Advisory
- support.apple.com/en-us/121842nvdVendor Advisory
- support.apple.com/en-us/121843nvdVendor Advisory
- support.apple.com/en-us/121844nvdVendor Advisory
- support.apple.com/en-us/121845nvdVendor Advisory
- seclists.org/fulldisclosure/2024/Dec/10nvd
- seclists.org/fulldisclosure/2024/Dec/12nvd
- seclists.org/fulldisclosure/2024/Dec/6nvd
- seclists.org/fulldisclosure/2024/Dec/7nvd
- seclists.org/fulldisclosure/2024/Dec/8nvd
News mentions
0No linked articles in our index yet.