SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityAnalyzed

CVE-2024-23222

Apple Multiple Products WebKit Type Confusion Vulnerability

KEVHIGH 8.8EPSS 10.6%

Does this matter?

Known to be exploited in the wild (CISA KEV, CISA remediation deadline 13 February 2024). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.

Description

A type confusion issue was addressed with improved checks. This issue is fixed in Safari 17.3, iOS 15.8.7 and iPadOS 15.8.7, iOS 16.7.5 and iPadOS 16.7.5, iOS 17.3 and iPadOS 17.3, macOS Monterey 12.7.3, macOS Sonoma 14.3, macOS Ventura 13.6.4, tvOS 17.3, visionOS 1.0.2. Processing maliciously crafted web content may lead to arbitrary code execution. This fix associated with the Coruna exploit was shipped in iOS 17.3 on January 22, 2024. This update brings that fix to devices that cannot update to the latest iOS version.

CVSS 3.1
8.8 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS
10.59% probability · 96th percentile
CISA KEV
Listed 23 January 2024 · due 13 February 2024
Weakness
CWE-843
Affected
apple/safari · apple/ipados · apple/iphone os · apple/macos · apple/tvos · apple/visionos
Source
product-security@apple.com

CISA notes

Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. https://support.apple.com/en-us/HT214055, https://support.apple.com/en-us/HT214056, https://support.apple.com/en-us/HT214057, https://support.apple.com/en-us/HT214058, https://support.apple.com/en-us/HT214059, https://support.apple.com/en-us/HT214061, https://support.apple.com/en-us/HT214063 ; https://nvd.nist.gov/vuln/detail/CVE-2024-23222

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.