HTTP: Apple macOS ImageIO File Parsing Heap Buffer Overflow

This signature detects attempts to exploit a known vulnerability against Apple macOS ImageIO. A successful attack can lead to a buffer overflow and arbitrary remote code execution within the context of the Apple macOS.

Extended Description

An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in macOS Ventura 13.7, iOS 17.7 and iPadOS 17.7, visionOS 2, watchOS 11, macOS Sequoia 15, iOS 18 and iPadOS 18, macOS Sonoma 14.7, tvOS 18. Processing an image may lead to a denial-of-service.

Affected Products

Apple ipados

Short Name
HTTP:STC:APPLE-MACOS-IMG-IO-BO
Severity
Major
Recommended
True
Recommended Action
Drop
Category
HTTP
Keywords
Apple Buffer CVE-2024-40777 CVE-2024-44176 File Heap ImageIO Overflow Parsing macOS
Release Date
04/03/2025
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3796
False Positive
Unknown
Vendors

Apple

Found a potential security threat?