The issue was addressed with improved input sanitization. This issue is fixed in Apple Music 1.5.0.152 for Windows. Processing maliciously crafted web content may disclose internal states of the app.
References
History

Mon, 24 Mar 2025 18:45:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple music
Microsoft
Microsoft windows 10 22h2
Microsoft windows 11 24h2
Weaknesses NVD-CWE-noinfo
CPEs cpe:2.3:a:apple:music:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_10_22h2:-:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_10_22h2:-:*:*:*:*:*:x86:*
cpe:2.3:o:microsoft:windows_11_24h2:-:*:*:*:*:*:arm64:*
Vendors & Products Apple
Apple music
Microsoft
Microsoft windows 10 22h2
Microsoft windows 11 24h2

Thu, 16 Jan 2025 15:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-79
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 15 Jan 2025 19:45:00 +0000

Type Values Removed Values Added
Description The issue was addressed with improved input sanitization. This issue is fixed in Apple Music 1.5.0.152 for Windows. Processing maliciously crafted web content may disclose internal states of the app.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published: 2025-01-15T19:35:55.404Z

Updated: 2025-03-24T17:43:00.456Z

Reserved: 2024-12-03T22:50:35.512Z

Link: CVE-2024-54540

cve-icon Vulnrichment

Updated: 2025-01-16T14:50:57.344Z

cve-icon NVD

Status : Modified

Published: 2025-01-15T20:15:28.703

Modified: 2025-03-24T18:15:20.780

Link: CVE-2024-54540

cve-icon Redhat

No data.