ZeroHour

CVE-2024-23225

KEVmass

Memory Corruption Kernel Protection Bypass in Apple iOS, macOS, tvOS, visionOS

CISA: Apple Multiple Products Memory Corruption Vulnerability

CVSS 3.1
7.8 high
EPSS
1%p73
Published
()
KEV added
AI analysis

CVE-2024-23225 is a memory-corruption flaw (CWE-787, out-of-bounds write) in the kernels of Apple's iOS, iPadOS, macOS, tvOS, visionOS and watchOS, addressed with improved memory validation in Apple's March 2024 updates. It is triggered locally (CVSS AV:L/PR:L/UI:N) after an attacker has already obtained arbitrary kernel read and write capability, typically as the final stage of an exploit chain, and requires no user interaction. Successful abuse lets the attacker bypass the kernel's memory protections, converting an existing kernel read/write primitive into deeper and more reliable system compromise. Affected users are those running iPhone/iPad software older than iOS/iPadOS 17.4 (or 16.7.6 on the iOS 16 line), Macs older than macOS Sonoma 14.4 / Ventura 13.6.5 / Monterey 12.7.4, Apple TV units older than tvOS 17.4, Apple Vision Pro units older than visionOS 1.1, and Apple Watch units older than watchOS 10.4. Apple has stated the issue may have been exploited in the wild, CISA added it to the KEV on 2024-03-06 as part of the March 2024 emergency update batch, and EPSS currently assigns a 1.5% probability of exploitation within 30 days (72nd percentile).

What to do: Patch immediately to iOS/iPadOS 17.4 (or 16.7.6 for devices that cannot run 17), macOS Sonoma 14.4 / Ventura 13.6.5 / Monterey 12.7.4, tvOS 17.4, visionOS 1.1 and watchOS 10.4; there is no known workaround, so updating is the only mitigation. Because the flaw is KEV-listed, federal agencies must apply the vendor fixes within the BOD 22-01 deadline, and all defenders should verify installed OS versions fleet-wide (e.g., via MDM) and prioritize internet-facing and high-risk users.

Affected
Apple iOS (iPhone)All versions prior to 17.4; versions on the iOS 16 line prior to 16.7.6
Apple iPadOSAll versions prior to 17.4; versions on the iPadOS 16 line prior to 16.7.6
Apple macOS (Sonoma)Prior to 14.4
Apple macOS (Ventura)Prior to 13.6.5
Apple macOS (Monterey)Prior to 12.7.4
Apple tvOS (Apple TV)Prior to 17.4
Apple visionOS (Apple Vision Pro)Prior to 1.1
Apple watchOS (Apple Watch)Prior to 10.4
Estimated exposure
mass≈2 billion active Apple devices (combined installed base); virtually all devices on pre-March 2024 OS builds were affected at disclosure — Estimate based on Apple's publicly reported active installed base of roughly 2 billion devices (2023) spanning iPhone, iPad, Mac, Apple Watch, Apple TV and Vision Pro, every one of which was exposed if it ran an OS version older than the…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A memory corruption issue was addressed with improved validation. This issue is fixed in iOS 16.7.6 and iPadOS 16.7.6, iOS 17.4 and iPadOS 17.4, macOS Monterey 12.7.4, macOS Sonoma 14.4, macOS Ventura 13.6.5, tvOS 17.4, visionOS 1.1, watchOS 10.4. An attacker with arbitrary kernel read and write capability may be able to bypass kernel memory protections. Apple is aware of a report that this issue may have been exploited.

CISA Known Exploited Vulnerability
Affected
Apple Multiple Products
Required action
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Due date
Ransomware use
Unknown
Vendors
apple
Products
ipados, iphone os, macos, tvos, visionos, watchos
Weakness
CWE-787
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news