CVE-2024-54535 Details
Description
A path handling issue was addressed with improved logic. This issue is fixed in iOS 18.1 and iPadOS 18.1, macOS Sequoia 15.1, visionOS 2.1, watchOS 11.1. An attacker with access to calendar data could also read reminders.
A path handling vulnerability has been identified in the Calendar app on watchOS 11.1, visionOS 2.1, iOS 18.1, and iPadOS 18.1. This vulnerability allows an attacker with access to calendar data to also read reminders. The issue was addressed with improved logic.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jan 16, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://support.apple.com/en-us/121563 | [email protected] | Vendor Advisory |
| https://support.apple.com/en-us/121564 | [email protected] | |
| https://support.apple.com/en-us/121565 | [email protected] | Vendor Advisory |
| https://support.apple.com/en-us/121566 | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-22 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') | [email protected] |
| CWE-22 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| apple ipados | < 18.1 |
CPE
Remediation
| |
| apple iphone os | < 18.1 |
CPE
Remediation
| |
| apple visionos | < 2.1 |
CPE
Remediation
| |
| apple watchos | < 11.1 |
CPE
Remediation
| |
Change History
7 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Apr 2, 2026 | CVE Modified | [email protected] |
| Jan 23, 2025 | CVE Modified | CISA-ADP |
| Jan 17, 2025 | CVE Modified | CISA-ADP |
| Jan 16, 2025 | Initial Analysis | [email protected] |
| Jan 15, 2025 | New CVE Received | [email protected] |