CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

Breaking the Sound Barrier, Part II: Exploiting CVE-2024-54529

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 571

As cited

Copy frozen at (site build).

vulnerabilities

Breaking the Sound Barrier, Part II: Exploiting CVE-2024-54529

A security researcher details the exploitation of CVE-2024-54529, a type confusion vulnerability in macOS coreaudiod system daemon discovered through knowledge-driven fuzzing. The vulnerability in the CoreAudio framework's Mach message handlers allows attackers to hijack control flow by crafting a pointer chain through heap memory to dereference a controlled fake vtable.

Why it matters: macOS users running vulnerable versions of CoreAudio are at risk of local privilege escalation or code execution if an attacker can craft and deliver a malicious Mach message; security teams should monitor for patched versions and assess exposure in their macOS deployments.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

Breaking the Sound Barrier, Part II: Exploiting CVE-2024-54529

A security researcher details the exploitation of CVE-2024-54529, a type confusion vulnerability in macOS coreaudiod system daemon discovered through knowledge-driven fuzzing. The vulnerability in the CoreAudio framework's Mach message handlers allows attackers to hijack control flow by crafting a pointer chain through heap memory to dereference a controlled fake vtable.

Why it matters: macOS users running vulnerable versions of CoreAudio are at risk of local privilege escalation or code execution if an attacker can craft and deliver a malicious Mach message; security teams should monitor for patched versions and assess exposure in their macOS deployments.

Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary