HIGH

CVE-2024-23296

Apple Ipados 2024-03-05 CVSS v3.1
CVSS
7.8
KEV

Description

A memory corruption issue was addressed with improved validation. This issue is fixed in iOS 16.7.8 and iPadOS 16.7.8, iOS 17.4 and iPadOS 17.4, macOS Monterey 12.7.6, macOS Sonoma 14.4, macOS Ventura 13.6.7, tvOS 17.4, visionOS 1.1, watchOS 10.4. An attacker with arbitrary kernel read and write capability may be able to bypass kernel memory protections. Apple is aware of a report that this issue may have been exploited.

Summary dbcve.org

This is a memory corruption vulnerability in Apple kernels that allows an attacker with pre-existing arbitrary kernel read/write capabilities to bypass additional kernel memory protections. The issue was addressed through improved validation, suggesting insufficient bounds checking or improper memory handling in kernel code.

Mitigation

Apply the vendor-supplied patches by updating affected devices to iOS 16.7.8/17.4+, macOS 12.7.6/13.6.7/14.4+, tvOS 17.4, visionOS 1.1, or watchOS 10.4. Given confirmed active exploitation, prioritize critical assets immediately.

Weakness (CWE)

CWE-787 Out-of-bounds Write

EPSS Score

1.41%
Probability of exploitation in next 30 days
71.1th percentile

References

https://support.apple.com/en-us/120881 Release Notes, Vendor Advisory https://support.apple.com/en-us/120882 Release Notes, Vendor Advisory https://support.apple.com/en-us/120883 Release Notes, Vendor Advisory https://support.apple.com/en-us/120893 Release Notes, Vendor Advisory https://support.apple.com/en-us/120895 Release Notes, Vendor Advisory https://support.apple.com/en-us/120898 Release Notes, Vendor Advisory https://support.apple.com/en-us/120900 Release Notes, Vendor Advisory https://support.apple.com/en-us/120910 Release Notes, Vendor Advisory http://seclists.org/fulldisclosure/2024/Jul/20 Mailing List, Third Party Advisory http://seclists.org/fulldisclosure/2024/Mar/18 Mailing List, Third Party Advisory http://seclists.org/fulldisclosure/2024/Mar/21 Mailing List, Third Party Advisory http://seclists.org/fulldisclosure/2024/Mar/24 Mailing List, Third Party Advisory http://seclists.org/fulldisclosure/2024/Mar/25 Mailing List, Third Party Advisory http://seclists.org/fulldisclosure/2024/Mar/26 Mailing List, Third Party Advisory http://seclists.org/fulldisclosure/2024/May/11 Mailing List, Third Party Advisory http://seclists.org/fulldisclosure/2024/May/13 Mailing List, Third Party Advisory https://support.apple.com/en-us/HT214081 Vendor Advisory https://support.apple.com/kb/HT214081 Vendor Advisory https://support.apple.com/kb/HT214084 Vendor Advisory https://support.apple.com/kb/HT214086 Vendor Advisory https://support.apple.com/kb/HT214087 Vendor Advisory https://support.apple.com/kb/HT214088 Vendor Advisory https://support.apple.com/kb/HT214100 Vendor Advisory https://support.apple.com/kb/HT214107 Vendor Advisory https://support.apple.com/kb/HT214118 Vendor Advisory https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2024-23296 US Government Resource
View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE