CVE-2024-23222

Summary

A type confusion issue was addressed with improved checks. This issue is fixed in tvOS 17.3, iOS 17.3 and iPadOS 17.3, macOS Sonoma 14.3, iOS 16.7.5 and iPadOS 16.7.5, Safari 17.3, macOS Ventura 13.6.4, macOS Monterey 12.7.3, visionOS 1.0.2. Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been exploited.

Severity
High
Severity Score

8.8

Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

CWE-ID

CWE-843

Vulnerability ID
CVE-2024-23222
Severity
High
Severity Score
8.8
Summary
A type confusion issue was addressed with improved checks. This issue is fixed in tvOS 17.3, iOS 17.3 and iPadOS 17.3, macOS Sonoma 14.3, iOS 16.7.5 and iPadOS 16.7.5, Safari 17.3, macOS Ventura 13.6.4, macOS Monterey 12.7.3, visionOS 1.0.2. Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been exploited.
References
https://support.apple.com/en-us/HT214058 https://support.apple.com/en-us/HT214059 https://support.apple.com/en-us/HT214063 https://support.apple.com/en-us/HT214055 https://support.apple.com/en-us/HT214056 https://support.apple.com/en-us/HT214061 https://support.apple.com/en-us/HT214057 https://support.apple.com/en-us/HT214070
Mitigation and Patches
https://access.redhat.com/security/cve/CVE-2024-23222
Exploits
https://support.apple.com/en-us/HT214059 https://www.cisa.gov/known-exploited-vulnerabilities-catalog
Metasploit Payload
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CWE ID
CWE-843

See SecOps Solution
in action

Schedule Demo