Record summary

CVE-2024-23225 has a selected CVSS score of 7.8 (high). CISA lists CVE-2024-23225 in KEV.

Description

A memory corruption issue was addressed with improved validation. This issue is fixed in iOS 16.7.6 and iPadOS 16.7.6, iOS 17.4 and iPadOS 17.4, macOS Monterey 12.7.4, macOS Sonoma 14.4, macOS Ventura 13.6.5, tvOS 17.4, visionOS 1.1, watchOS 10.4. An attacker with arbitrary kernel read and write capability may be able to bypass kernel memory protections. Apple is aware of a report that this issue may have been exploited.

Description source: CVE List

Exploitation context

Known exploitation

CISA KEV
Listed · Mar 6, 2024 · CISA
VulnCheck KEV
Listed · Mar 5, 2024 · VulnCheck
Reported exploitation
Observed · VulnCheck

CISA SSVC decision

ExploitationActive
AutomatableNo
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Aug 28, 2024 · Source: CVE List

Affected products and versions

8
ProductSourceVersion rangeStatus
CISAVersion data not supplied
CVE ListBefore 16.7.6affected
Before 17.4affected

Default status: unknown

CVE ListBefore 12.7.4affected
Before 13.6.5affected
Before 14.4affected
12.0.0 to < 12.7.4affected
13.0 to < 13.6.5affected
14.0 to < 14.4affected

Default status: unknown

CVE ListBefore 17.4affected

Default status: unknown

CVE ListBefore 1.1affected

Default status: unknown

CVE ListBefore 10.4affected

Default status: unknown

CVE List17.0 to < 17.4affected
Before 16.7.6affected

Default status: unknown

CVE ListBefore 16.7.6affected
17.0 to < 17.4affected

References

Showing 12 of 27