iOS 17.5 Includes These 15 Security Fixes, But One Causes Another Bug

iOS 17.5 and iPadOS 17.5 include 15 security patches for the iPhone and iPad, according to a recently-published Apple support document, but unfortunately one of the patches has led to a software bug affecting alternative app marketplaces.

iOS 17
According to Mysk, a security patch related to the MarketplaceKit framework has resulted in a bug that prevents iPhone users in the EU from reinstalling an alternative app marketplace like AltStore if they happen to delete the app after initially installing it. Apple will likely fix this issue in a subsequent update, such as iOS 17.5.1.

In related news, one security researcher has complained that the iOS kernel vulnerability they discovered was not eligible for payment under the Apple Security Bounty program. It is listed in the iOS 17.5 security fixes below under "AppleAVD."

Apple's full list of security patches included in iOS 17.5 and iPadOS 17.5:

AppleAVD

Available for: iPhone XS and later, iPad Pro 12.9-inch 2nd generation and later, iPad Pro 10.5-inch, iPad Pro 11-inch 1st generation and later, iPad Air 3rd generation and later, iPad 6th generation and later, and iPad mini 5th generation and later

Impact: An app may be able to execute arbitrary code with kernel privileges

Description: The issue was addressed with improved memory handling.

CVE-2024-27804: Meysam Firouzi (@R00tkitSMM)

AppleMobileFileIntegrity

Available for: iPhone XS and later, iPad Pro 12.9-inch 2nd generation and later, iPad Pro 10.5-inch, iPad Pro 11-inch 1st generation and later, iPad Air 3rd generation and later, iPad 6th generation and later, and iPad mini 5th generation and later

Impact: An attacker may be able to access user data

Description: A logic issue was addressed with improved checks.

CVE-2024-27816: Mickey Jin (@patch1t)

AVEVideoEncoder

Available for: iPhone XS and later, iPad Pro 12.9-inch 2nd generation and later, iPad Pro 10.5-inch, iPad Pro 11-inch 1st generation and later, iPad Air 3rd generation and later, iPad 6th generation and later, and iPad mini 5th generation and later

Impact: An app may be able to disclose kernel memory

Description: The issue was addressed with improved memory handling.

CVE-2024-27841: an anonymous researcher

Find My

Available for: iPhone XS and later, iPad Pro 12.9-inch 2nd generation and later, iPad Pro 10.5-inch, iPad Pro 11-inch 1st generation and later, iPad Air 3rd generation and later, iPad 6th generation and later, and iPad mini 5th generation and later

Impact: A malicious application may be able to determine a user's current location

Description: A privacy issue was addressed by moving sensitive data to a more secure location.

CVE-2024-27839: Alexander Heinrich, SEEMOO, TU Darmstadt (@Sn0wfreeze), and Shai Mishali (@freak4pc)

Kernel

Available for: iPhone XS and later, iPad Pro 12.9-inch 2nd generation and later, iPad Pro 10.5-inch, iPad Pro 11-inch 1st generation and later, iPad Air 3rd generation and later, iPad 6th generation and later, and iPad mini 5th generation and later

Impact: An attacker may be able to cause unexpected app termination or arbitrary code execution

Description: The issue was addressed with improved memory handling.

CVE-2024-27818: pattern-f (@pattern_F_) of Ant Security Light-Year Lab

Libsystem

Available for: iPhone XS and later, iPad Pro 12.9-inch 2nd generation and later, iPad Pro 10.5-inch, iPad Pro 11-inch 1st generation and later, iPad Air 3rd generation and later, iPad 6th generation and later, and iPad mini 5th generation and later

Impact: An app may be able to access protected user data

Description: A permissions issue was addressed by removing vulnerable code and adding additional checks.

CVE-2023-42893: an anonymous researcher

Maps

Available for: iPhone XS and later, iPad Pro 12.9-inch 2nd generation and later, iPad Pro 10.5-inch, iPad Pro 11-inch 1st generation and later, iPad Air 3rd generation and later, iPad 6th generation and later, and iPad mini 5th generation and later

Impact: An app may be able to read sensitive location information

Description: A path handling issue was addressed with improved validation.

CVE-2024-27810: LFY@secsys of Fudan University

MarketplaceKit

Available for: iPhone XS and later

Impact: A maliciously crafted webpage may be able to distribute a script that tracks users on other webpages

Description: A privacy issue was addressed with improved client ID handling for alternative app marketplaces.

CVE-2024-27852: Talal Haj Bakry and Tommy Mysk of Mysk Inc. (@mysk_co)

Notes

Available for: iPhone XS and later, iPad Pro 12.9-inch 2nd generation and later, iPad Pro 10.5-inch, iPad Pro 11-inch 1st generation and later, iPad Air 3rd generation and later, iPad 6th generation and later, and iPad mini 5th generation and later

Impact: An attacker with physical access to an iOS device may be able to access notes from the lock screen

Description: This issue was addressed through improved state management.

CVE-2024-27835: Andr.Ess

RemoteViewServices

Available for: iPhone XS and later, iPad Pro 12.9-inch 2nd generation and later, iPad Pro 10.5-inch, iPad Pro 11-inch 1st generation and later, iPad Air 3rd generation and later, iPad 6th generation and later, and iPad mini 5th generation and later

Impact: An attacker may be able to access user data

Description: A logic issue was addressed with improved checks.

CVE-2024-27816: Mickey Jin (@patch1t)

Screenshots

Available for: iPhone XS and later, iPad Pro 12.9-inch 2nd generation and later, iPad Pro 10.5-inch, iPad Pro 11-inch 1st generation and later, iPad Air 3rd generation and later, iPad 6th generation and later, and iPad mini 5th generation and later

Impact: An attacker with physical access may be able to share items from the lock screen

Description: A permissions issue was addressed with improved validation.

CVE-2024-27803: an anonymous researcher

Shortcuts

Available for: iPhone XS and later, iPad Pro 12.9-inch 2nd generation and later, iPad Pro 10.5-inch, iPad Pro 11-inch 1st generation and later, iPad Air 3rd generation and later, iPad 6th generation and later, and iPad mini 5th generation and later

Impact: A shortcut may output sensitive user data without consent

Description: A path handling issue was addressed with improved validation.

CVE-2024-27821: Kirin (@Pwnrin), zbleet, and Csaba Fitzl (@theevilbit) of Kandji

Sync Services

Available for: iPhone XS and later, iPad Pro 12.9-inch 2nd generation and later, iPad Pro 10.5-inch, iPad Pro 11-inch 1st generation and later, iPad Air 3rd generation and later, iPad 6th generation and later, and iPad mini 5th generation and later

Impact: An app may be able to bypass Privacy preferences

Description: This issue was addressed with improved checks

CVE-2024-27847: Mickey Jin (@patch1t)

Voice Control

Available for: iPhone XS and later, iPad Pro 12.9-inch 2nd generation and later, iPad Pro 10.5-inch, iPad Pro 11-inch 1st generation and later, iPad Air 3rd generation and later, iPad 6th generation and later, and iPad mini 5th generation and later

Impact: An attacker may be able to elevate privileges

Description: The issue was addressed with improved checks.

CVE-2024-27796: ajajfxhj

WebKit

Available for: iPhone XS and later, iPad Pro 12.9-inch 2nd generation and later, iPad Pro 10.5-inch, iPad Pro 11-inch 1st generation and later, iPad Air 3rd generation and later, iPad 6th generation and later, and iPad mini 5th generation and later

Impact: An attacker with arbitrary read and write capability may be able to bypass Pointer Authentication

Description: The issue was addressed with improved checks.

WebKit Bugzilla: 272750
CVE-2024-27834: Manfred Paul (@_manfp) working with Trend Micro's Zero Day Initiative

Apple released iOS 17.5 and iPadOS 17.5 on Monday following around six weeks of beta testing.

Related Forums: iOS 17, iPadOS 17

Popular Stories

Generic iOS 19 Feature Mock Light

iOS 19 Rumored to Include These New Features for Your iPhone

Saturday March 1, 2025 11:00 am PST by
iOS 19 is still around three months away from being unveiled, but there are plenty of rumors about the upcoming update. Below, we recap iOS 19 rumors so far. Redesigned Camera App A leak earlier this year allegedly revealed a redesigned Camera app coming with iOS 19. On his YouTube channel Front Page Tech in January, Jon Prosser shared a video showing what the new Camera app will...
iOS 18

Apple Says iOS 18.4 Will Be Released in April With These New Features

Wednesday February 26, 2025 7:15 am PST by
In a recent press release, Apple confirmed that iOS 18.4 will be released in April. From the Apple News+ Food announcement:Coming with iOS 18.4 and iPadOS 18.4 in April, Apple News+ subscribers will have access to Apple News+ Food, a new section that will feature tens of thousands of recipes — as well as stories about restaurants, healthy eating, kitchen essentials, and more — from the...
Generic iPhone 17 Feature With Full Width Dynamic Island

Latest iPhone 17 Series CAD Images in Line With Redesign Rumors

Friday February 28, 2025 2:51 am PST by
Apple is expected to embrace a new camera system design for some models in its upcoming iPhone 17 series, and the latest purported CAD images don't deviate from what we have been hearing lately about Apple's new lineup. If you do not like the sound of an iPhone with a Google Pixel-style camera bar, look away now. Seasoned leaker Sonny Dickson shared the following images in a post on X...
apple intelligence black

These New Apple Intelligence Features Are Coming in iOS 18.4

Friday February 28, 2025 3:17 pm PST by
iOS 18.4 was supposed to bring new Apple Intelligence Siri features, but Apple ended up needing to pull those capabilities from the update to continue testing. There are fewer new Apple Intelligence additions now, but there are still some new features that will make the update worth installing when it comes out in April. Priority Notifications Apple introduced Priority Notifications back at ...
iphone 16e usb c feature

Apple Provides Reason for iPhone 16e's Lack of MagSafe

Friday February 28, 2025 4:39 am PST by
Apple has offered a reason why the iPhone 16e doesn't include MagSafe, one of the more notable omissions from its latest entry-level smartphone. According to Apple representatives who spoke to Daring Fireball's John Gruber, MagSafe is not included in the iPhone 16e because "most people in the iPhone 16e's target audience exclusively charge their phones by plugging them into a charging...
Apple MacBook Air 2 up hero 240304 feature

New MacBook Air Announcement Reportedly 'Imminent' — Here's When

Sunday March 2, 2025 5:40 am PST by
With the iPhone 16e now in the hands of customers, Apple reportedly plans to move on to its next product announcement in the coming days. Apple plans to announce new MacBook Air models with the M4 chip "as early as this week," according to Bloomberg's Mark Gurman. "I expect the M4 MacBook Air to be introduced as early as this week," said Gurman, in a post shared on X today. "Inventory has ...
Apple AirPort Routers

Apple's Discontinued Line of AirPort Wi-Fi Routers Could Return in an Unexpected Way

Saturday March 1, 2025 10:00 am PST by
Throughout the 2000s and 2010s, Apple offered a line of Wi-Fi routers that it referred to as AirPort base stations. There was a standard AirPort Express, a higher-end AirPort Extreme with more advanced networking features, and an AirPort Time Capsule that doubled as an external storage drive for backing up a Mac with Time Machine. Apple discontinued the AirPort line in 2018, but the company...
apple c1

How Fast is Apple's First-Ever 5G Modem? The Results Are Surprising

Friday February 28, 2025 10:08 am PST by
iPhone 16e reviews are now out, and Apple's custom-designed C1 modem has been put to the test. The results so far are quite surprising, as the C1's speeds are not as slow compared to Qualcomm modems as originally expected. While the C1 does not support ultra-fast mmWave 5G in the U.S., it appears to offer comparable 5G performance to Qualcomm's Snapdragon X71 modem found in the iPhone 16,...
airpods pro purple

Here's When AirPods Pro 3 Are Rumored to Launch

Monday February 24, 2025 9:14 am PST by
According to a post on X today from a leaker known as Kosutami, Apple plans to launch AirPods Pro 3 in May or June this year. The leaker also claimed that an AirTag 2 will launch around the same time. Kosutami is best known as a collector of prototype Apple hardware, but they have occasionally shared accurate information about Apple's future product plans. For example, they accurately...

Top Rated Comments

Tony_YYZ Avatar
11 months ago

Who would be positive about a bug that worsens the user experience in an optional system feature?
Some folks on here really don’t want others to have the ability to install whatever they want on their own phones. Like it personally offends them and affects their lives somehow.
Score: 21 Votes (Like | Disagree)
jdavid_rp Avatar
11 months ago

some call it a bug, one might call it a feature. a great one, one might say.
Who would be positive about a bug that worsens the user experience in an optional system feature?
Score: 13 Votes (Like | Disagree)
Havalo Avatar
11 months ago
Those boys at NSO and other three acronym agencies aren’t going to be too happy that Apple has patched them… ?

Cat and mouse game continues…
Score: 10 Votes (Like | Disagree)
hagar Avatar
11 months ago
I have installed my first AltStore (SetApp Mobile - in beta). Works great. Very intuitive, no dramatic warnings by Apple, everything works as expected.

The only thing is that you get a warning when trying to install the store. You first need to approve this manually in Settings. For each developer.

Otherwise there’s no difference with App Store apps. Curious how smooth app updates will work.
Score: 9 Votes (Like | Disagree)
bradman83 Avatar
11 months ago
Apple after accidentally causing glitches in alternate app marketplaces
Score: 8 Votes (Like | Disagree)
Edsel Avatar
11 months ago
Reading about these 21st century security updates always has me yearning for 19th century parchment paper, quill pens and daguerreotype camera.
Score: 8 Votes (Like | Disagree)