Apple emergency security updates fix two new iOS zero
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2024-23222 | Apple WebKit Type Confusion Enables Arbitrary Code Execution Across iOS, macOS, tvOS CVE-2024-23222 is a type confusion flaw (CWE-843) in Apple's WebKit engine that allows arbitrary code execution when a device processes maliciously crafted web content, for example when a user is lured into loading attacker-controlled web pages in Safari or another WebKit-based view (the CVSS vector confirms user interaction is required). It affects a broad slice of the Apple ecosystem: Safari, iPhone OS/iPadOS on the iOS 15, 16 and 17 branches, macOS Monterey/Ventura/Sonoma, tvOS and visionOS, prior to the January 22, 2024 fixes. A successful attacker gains code execution on the target device with high impact on confidentiality, integrity and availability (CVSS 3.1: 8.8). The flaw was fixed in Safari 17.3, iOS/iPadOS 17.3, and backported to iOS/iPadOS 15.8.7 and 16.7.5 for devices that cannot upgrade to iOS 17, plus macOS Monterey 12.7.3, Ventura 13.6.4, Sonoma 14.3, tvOS 17.3 and visionOS 1.0.2. Exploitation is confirmed in the wild: the vulnerability was added to CISA KEV on 2024-01-23, one day after the fixes shipped, and is associated with the Coruna exploit kit, which reportedly chains multiple exploits to target iOS devices including older versions. Do: Update all affected devices to Safari 17.3, iOS/iPadOS 17.3 (or the iOS/iPadOS 15.8.7 and 16.7.5 backports for devices that cannot run 17), macOS Monterey 12.7.3, macOS Ventura 13.6.4, macOS Sonoma 14.3, tvOS 17.3 and visionOS 1.0.2. Prioritize endpoints used for web browsing and mobile users, since exploitation only requires a user to process crafted web content. The CISA KEV listing (added 2024-01-23) makes applying these vendor updates mandatory under the KEV required action, so verify fleet versions and confirm no devices remain on pre-patch builds. | 8.8 | 11% | KEV |
| massover 1 billion active Apple devices (effectively Apple's entire unpatched iPhone/iPad/Mac/Apple TV fleet) | |
| CVE-2024-23225 +1 in the same advisory: …23296 | Memory Corruption Kernel Protection Bypass in Apple iOS, macOS, tvOS, visionOS CVE-2024-23225 is a memory-corruption flaw (CWE-787, out-of-bounds write) in the kernels of Apple's iOS, iPadOS, macOS, tvOS, visionOS and watchOS, addressed with improved memory validation in Apple's March 2024 updates. It is triggered locally (CVSS AV:L/PR:L/UI:N) after an attacker has already obtained arbitrary kernel read and write capability, typically as the final stage of an exploit chain, and requires no user interaction. Successful abuse lets the attacker bypass the kernel's memory protections, converting an existing kernel read/write primitive into deeper and more reliable system compromise. Affected users are those running iPhone/iPad software older than iOS/iPadOS 17.4 (or 16.7.6 on the iOS 16 line), Macs older than macOS Sonoma 14.4 / Ventura 13.6.5 / Monterey 12.7.4, Apple TV units older than tvOS 17.4, Apple Vision Pro units older than visionOS 1.1, and Apple Watch units older than watchOS 10.4. Apple has stated the issue may have been exploited in the wild, CISA added it to the KEV on 2024-03-06 as part of the March 2024 emergency update batch, and EPSS currently assigns a 1.5% probability of exploitation within 30 days (72nd percentile). Do: Patch immediately to iOS/iPadOS 17.4 (or 16.7.6 for devices that cannot run 17), macOS Sonoma 14.4 / Ventura 13.6.5 / Monterey 12.7.4, tvOS 17.4, visionOS 1.1 and watchOS 10.4; there is no known workaround, so updating is the only mitigation. Because the flaw is KEV-listed, federal agencies must apply the vendor fixes within the BOD 22-01 deadline, and all defenders should verify installed OS versions fleet-wide (e.g., via MDM) and prioritize internet-facing and high-risk users. | 7.8 | 1% | KEV |
| mass≈2 billion active Apple devices (combined installed base); virtually all devices on pre-March 2024 OS builds were affected at disclosure |
Full article288 words · extracted from securityaffairs.com · click to collapse

Apple released emergency security updates to address two new iOS zero-day vulnerabilities actively exploited in the wild against iPhone users.
Apple released emergency security updates to address two iOS zero-day vulnerabilities, respectively tracked as CVE-2024-23225 and CVE-2024-23296, that were exploited in attacks against iPhone devices.
CVE-2024-23225 is a Kernel memory corruption flaw, the company addressed it with improved validation.
“An attacker with arbitrary kernel read and write capability may be able to bypass kernel memory protections. Apple is aware of a report that this issue may have been exploited.” reads the advisory.
CVE-2024-23296 is a RTKit memory corruption flaw, the company addressed it with improved validation.
“An attacker with arbitrary kernel read and write capability may be able to bypass kernel memory protections. Apple is aware of a report that this issue may have been exploited.” continues the advisory.
Apple confirmed both vulnerabilities are actively exploited.
“Apple is aware of a report that this issue may have been exploited,” states the company.
Impacted devices are iPhone XS and later, iPad Pro 12.9-inch 2nd generation and later, iPad Pro 10.5-inch, iPad Pro 11-inch 1st generation and later, iPad Air 3rd generation and later, iPad 6th generation and later, and iPad mini 5th generation and later.
The IT giant addressed the two vulnerabilities with the release of iOS 17.4, iPadOS 17.4, iOS 16.76, and iPad 16.7.6.
iPhone vulnerabilities are usually exploited by commercial spyware vendors or nation-state actors, in many cases, the targets were dissidents and journalists.
Below is the list of zero-day addressed by Apple this year:
January 2024 – CVE-2024-23222: type confusion issue that resides in the WebKit
Follow me on Twitter: @securityaffairs and Facebook
(SecurityAffairs – hacking, zero-day)
Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/160048/hacking/apple-new-ios-zero-day-vulnerabilities.html