iOS 17.4.1

Apple walks back CVE-2024-27804, claims it’s non-exploitable & offers security researcher paltry $1,000 bounty

iPhone hacked matrix.

If you’ve been following along during the past couple of days, especially following the release of iOS & iPadOS 17.5, then you’ve likely heard about the new PoC for a kernel vulnerability in AppleAVD impacting iOS & iPadOS 17.4.1 and older called CVE-2024-27804, which Apple cited as having the potential impact for an app to execute arbitrary code with kernel privileges

Security researcher says PoC for kernel vulnerability targeting iOS 17.4.1 and older coming soon

iPhone hacked matrix.

Apple on Monday released iOS & iPadOS 17.5, with a substantial part of that update incorporating a handful of security patches. At the very top of Apple’s “About the security content of iOS 17.5 and iPadOS 17.5” web page is CVE-2024-27804, a peculiar kernel vulnerability in AppleAVD which had the potential impact of an app being able to execute arbitrary code with kernel privileges.