CVE-2024-40815: Apple iPadOS

High severity, CVSS 7.5. EPSS: 1.1% chance of exploitation in the next 30 days.

A race condition was addressed with additional validation. This issue is fixed in iOS 17.6 and iPadOS 17.6, macOS Sonoma 14.6, macOS Ventura 13.6.8, tvOS 17.6, watchOS 10.6. A malicious attacker with arbitrary read and write capability may be able to bypass Pointer Authentication.

Affected products

  • Apple iPadOS: before 17.6 (fixed in 17.6)
  • Apple iPhone OS: before 17.6 (fixed in 17.6)
  • Apple macOS: before 13.6.8 (fixed in 13.6.8); from 14.0, before 14.6 (fixed in 14.6)
  • Apple tvOS: before 17.6 (fixed in 17.6)
  • Apple watchOS: before 10.6 (fixed in 10.6)

Published 2024-07-29. Last modified 2026-06-17.