peter bassill · operator
$ cve CVE-2024-23222 JSON

CVE-2024-23222 KEV

8.8
HIGH · CVSS 3.1 · EPSS 10.6% (pctl 96)

Patch first

On CISA KEV — known exploited in the wild, due 2024-02-13.

Description

A type confusion issue was addressed with improved checks. This issue is fixed in Safari 17.3, iOS 15.8.7 and iPadOS 15.8.7, iOS 16.7.5 and iPadOS 16.7.5, iOS 17.3 and iPadOS 17.3, macOS Monterey 12.7.3, macOS Sonoma 14.3, macOS Ventura 13.6.4, tvOS 17.3, visionOS 1.0.2. Processing maliciously crafted web content may lead to arbitrary code execution. This fix associated with the Coruna exploit was shipped in iOS 17.3 on January 22, 2024. This update brings that fix to devices that cannot update to the latest iOS version.

Scoring

CVSS8.8 (HIGH, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS10.59% — more likely to be exploited than 96% of all CVEs
WeaknessCWE-843
On CISA KEVyes — remediate by 2024-02-13
Public exploitnone known
Published2024-01-23
Last modified2026-06-17

CISA KEV

NameApple Multiple Products WebKit Type Confusion Vulnerability
Added2024-01-23
Due2024-02-13
Vendor / productApple / Multiple Products
Ransomware usenone reported

Affected (6)

VendorProduct
appleipados
appleiphone os
applemacos
applesafari
appletvos
applevisionos

References

→ the Explorer  ·  watch your stack  ·  NVD