Threat actors may have exploited a zero
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2024-23296 | Kernel Memory Corruption in Apple iOS, iPadOS, macOS, tvOS, watchOS, visionOS CVE-2024-23296 is a memory corruption issue (CWE-787, out-of-bounds write) in the kernels of Apple's operating systems, addressed by Apple with improved validation in its March 2024 updates. Per Apple and the CVSS vector (AV:L/PR:L/UI:N), exploitation is local with low privileges and no user interaction: an attacker who has already gained arbitrary kernel read and write capability can use the flaw to bypass kernel memory protections, meaning it is typically used in an exploit chain after an initial kernel compromise. Successful abuse defeats hardened kernel memory restrictions, potentially giving the attacker broader control over the operating system and undermining kernel-level protections. Anyone running affected versions is exposed: iPhone/iPad on iOS/iPadOS prior to the 17.4 and 16.7.8 fixes, Macs prior to macOS Sonoma 14.4, Ventura 13.6.7 or Monterey 12.7.6, Apple TV prior to tvOS 17.4, Apple Watch prior to watchOS 10.4, and Vision Pro prior to visionOS 1.1. Apple has stated the issue may have been exploited in the wild, and CISA added it to the KEV catalog on 2024-03-06; no public proof-of-concept is known and ransomware use is unknown (EPSS 1.4%, 71st percentile). Do: Patch immediately to iOS/iPadOS 17.4 (or 16.7.8 for devices staying on iOS 16), macOS Sonoma 14.4 / Ventura 13.6.7 / Monterey 12.7.6, tvOS 17.4, watchOS 10.4 and visionOS 1.1; no workaround is documented, and CISA's KEV required action mandates applying vendor fixes (or discontinuing use) for federal agencies. Because the flaw is used to bypass kernel memory protections after an attacker already has kernel read/write, also ensure devices are current on all other Apple kernel security updates and inventory for any Apple phones, tablets, Macs or TVs running older OS versions. | 7.8 | 1% | KEV |
| masshundreds of millions of devices (Apple's active installed base exceeds 2 billion devices; affected iOS/macOS/tvOS/watchOS versions were current for most users… | |
| CVE-2024-27789 | A logic issue was addressed with improved checks. A logic issue was addressed with improved checks. This issue is fixed in iOS 16.7.8 and iPadOS 16.7.8, macOS Monterey 12.7.5, macOS Sonoma 14.4, macOS Ventura 13.6.7. An app may be able to access user-sensitive data. NVD description · AI analysis pending | 5.5 | <1% |
| — |
Full article305 words · extracted from securityaffairs.com · click to collapse

Apple rolled out urgent security updates to address code execution vulnerabilities in iPhones, iPads, and macOS.
Apple released urgent security updates to address multiple vulnerabilities in iPhones, iPads, macOS. The company also warns of a vulnerability patched in March that the company believes may have been exploited as a zero-day.
The issue impacts older iPhone devices, it is tracked as CVE-2024-23296 and is a memory corruption flaw in the RTKit.
— Ryan Naraine (@ryanaraine) May 13, 2024Apple documents at least 16 vulnerabilities on iPhones and iPads and called special attention to CVE-2024-23296, a memory corruption bug in RTKit that the company says “may have been exploited” prior to the availability of patches
Story https://t.co/pwTjHWdt0I
The Real-Time Kernel is a component of the operating system responsible for managing and executing tasks with strict timing requirements.
“An attacker with arbitrary kernel read and write capability may be able to bypass kernel memory protections.” reads the advisory published by Cupertino firm. “Apple is aware of a report that this issue may have been exploited.”
The IT giant fixed the memory corruption bug with improved validation, it released iOS 16.7.8 and iPadOS 16.7.8.
The company also addressed a logic issue, tracked as CVE-2024-27789, in the Foundation framework. The flaw can be exploited by an app to access user-sensitive data.
The flaw was reported by Mickey Jin (@patch1t), the company addressed the vulnerability with improved checks.
Security patches are available for iPhone 8, iPhone 8 Plus, iPhone X, iPad 5th generation, iPad Pro 9.7-inch, and iPad Pro 12.9-inch 1st generation
Apple released security patches to fix other issues in multiple products. The vulnerabilities fixed by the vendor can lead to arbitrary code execution, privilege escalation, denial-of-service attacks, and unauthorized access to data.
Follow me on Twitter: @securityaffairs and Facebook and Mastodon
(SecurityAffairs – hacking, zero-day)
Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/163096/hacking/apple-iphones-zero-day-exploited.html