CVE-2024-23225
Apple Multiple Products Memory Corruption Vulnerability
Record summary
CVE-2024-23225 has a selected CVSS score of 7.8 (high). CISA lists CVE-2024-23225 in KEV.
Description
A memory corruption issue was addressed with improved validation. This issue is fixed in iOS 16.7.6 and iPadOS 16.7.6, iOS 17.4 and iPadOS 17.4, macOS Monterey 12.7.4, macOS Sonoma 14.4, macOS Ventura 13.6.5, tvOS 17.4, visionOS 1.1, watchOS 10.4. An attacker with arbitrary kernel read and write capability may be able to bypass kernel memory protections. Apple is aware of a report that this issue may have been exploited.
Exploitation context
Known exploitation
- CISA KEV
- Listed · Mar 6, 2024 · CISA
- VulnCheck KEV
- Listed · Mar 5, 2024 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
CISA SSVC decision
CISA Coordinator · SSVC 2.0.3 · Evaluated Aug 28, 2024 · Source: CVE List
Affected products and versions
8| Product | Source | Version range | Status |
|---|---|---|---|
Multiple ProductsBrowse Apple / Multiple Products | CISA | Version data not supplied | |
iOS and iPadOSBrowse Apple / iOS and iPadOS | CVE List | Before 16.7.6 | affected |
| Before 17.4 | affected | ||
macOSBrowse Apple / macOSDefault status: unknown | CVE List | Before 12.7.4 | affected |
| Before 13.6.5 | affected | ||
| Before 14.4 | affected | ||
| 12.0.0 to < 12.7.4 | affected | ||
| 13.0 to < 13.6.5 | affected | ||
| 14.0 to < 14.4 | affected | ||
Default status: unknown | CVE List | Before 17.4 | affected |
visionOSBrowse Apple / visionOSDefault status: unknown | CVE List | Before 1.1 | affected |
watchOSBrowse Apple / watchOSDefault status: unknown | CVE List | Before 10.4 | affected |
ipad_osBrowse apple / ipad_osDefault status: unknown | CVE List | 17.0 to < 17.4 | affected |
| Before 16.7.6 | affected | ||
iphone_osBrowse apple / iphone_osDefault status: unknown | CVE List | Before 16.7.6 | affected |
| 17.0 to < 17.4 | affected | ||