CVE-2024-40777: Apple iPadOS

Medium severity, CVSS 5.5. EPSS: 7.7% chance of exploitation in the next 30 days.

An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in iOS 17.6 and iPadOS 17.6, macOS Sonoma 14.6, tvOS 17.6, visionOS 1.3, watchOS 10.6. Processing a maliciously crafted file may lead to unexpected app termination.

Affected products

  • Apple iPadOS: before 17.6 (fixed in 17.6)
  • Apple iPhone OS: before 17.6 (fixed in 17.6)
  • Apple macOS: from 14.0, before 14.6 (fixed in 14.6)
  • Apple tvOS: before 17.6 (fixed in 17.6)
  • Apple visionOS: before 1.3 (fixed in 1.3)
  • Apple watchOS: before 10.6 (fixed in 10.6)

Published 2024-07-29. Last modified 2026-06-17.