ZeroHour

CVE-2024-23296

KEVmass

Kernel Memory Corruption in Apple iOS, iPadOS, macOS, tvOS, watchOS, visionOS

CISA: Apple Multiple Products Memory Corruption Vulnerability

CVSS 3.1
7.8 high
EPSS
1%p71
Published
()
KEV added
AI analysis

CVE-2024-23296 is a memory corruption issue (CWE-787, out-of-bounds write) in the kernels of Apple's operating systems, addressed by Apple with improved validation in its March 2024 updates. Per Apple and the CVSS vector (AV:L/PR:L/UI:N), exploitation is local with low privileges and no user interaction: an attacker who has already gained arbitrary kernel read and write capability can use the flaw to bypass kernel memory protections, meaning it is typically used in an exploit chain after an initial kernel compromise. Successful abuse defeats hardened kernel memory restrictions, potentially giving the attacker broader control over the operating system and undermining kernel-level protections. Anyone running affected versions is exposed: iPhone/iPad on iOS/iPadOS prior to the 17.4 and 16.7.8 fixes, Macs prior to macOS Sonoma 14.4, Ventura 13.6.7 or Monterey 12.7.6, Apple TV prior to tvOS 17.4, Apple Watch prior to watchOS 10.4, and Vision Pro prior to visionOS 1.1. Apple has stated the issue may have been exploited in the wild, and CISA added it to the KEV catalog on 2024-03-06; no public proof-of-concept is known and ransomware use is unknown (EPSS 1.4%, 71st percentile).

What to do: Patch immediately to iOS/iPadOS 17.4 (or 16.7.8 for devices staying on iOS 16), macOS Sonoma 14.4 / Ventura 13.6.7 / Monterey 12.7.6, tvOS 17.4, watchOS 10.4 and visionOS 1.1; no workaround is documented, and CISA's KEV required action mandates applying vendor fixes (or discontinuing use) for federal agencies. Because the flaw is used to bypass kernel memory protections after an attacker already has kernel read/write, also ensure devices are current on all other Apple kernel security updates and inventory for any Apple phones, tablets, Macs or TVs running older OS versions.

Affected
Apple iOS (iPhone OS)versions before 16.7.8 (16.x branch) and before 17.4 (17.x branch); fixed in iOS 16.7.8 and iOS 17.4
Apple iPadOSversions before 16.7.8 (16.x branch) and before 17.4 (17.x branch); fixed in iPadOS 16.7.8 and iPadOS 17.4
Apple macOSMonterey before 12.7.6, Ventura before 13.6.7, Sonoma before 14.4; fixed in macOS Monterey 12.7.6, Ventura 13.6.7 and Sonoma 14.4
Apple tvOSversions before 17.4; fixed in tvOS 17.4
Apple visionOSversions before 1.1; fixed in visionOS 1.1
Apple watchOSversions before 10.4; fixed in watchOS 10.4
Estimated exposure
masshundreds of millions of devices (Apple's active installed base exceeds 2 billion devices; affected iOS/macOS/tvOS/watchOS versions were current for most users… — Based on Apple's publicly reported active install base of more than 2 billion devices and typical patch-adoption lag at the time of the March 2024 fixes, a large fraction of unpatched iPhones, iPads, Macs, Apple TVs and Apple Watches…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A memory corruption issue was addressed with improved validation. This issue is fixed in iOS 16.7.8 and iPadOS 16.7.8, iOS 17.4 and iPadOS 17.4, macOS Monterey 12.7.6, macOS Sonoma 14.4, macOS Ventura 13.6.7, tvOS 17.4, visionOS 1.1, watchOS 10.4. An attacker with arbitrary kernel read and write capability may be able to bypass kernel memory protections. Apple is aware of a report that this issue may have been exploited.

CISA Known Exploited Vulnerability
Affected
Apple Multiple Products
Required action
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Due date
Ransomware use
Unknown
Vendors
apple
Products
ipados, iphone os, macos, tvos, visionos, watchos
Weakness
CWE-787
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news