Buffer overflow in iPadOS and Apple iOS - CVE-2024-23225
Published: March 5, 2024
Vulnerability identifier: #VU87134
CSH Severity: High
CVSS v4 BT: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:A/U:Amber]
CVE-ID: CVE-2024-23225
CWE-ID: CWE-119
Exploitation vector: Local access
Exploit availability:
The vulnerability is being exploited in the wild
Vulnerability details
The vulnerability allows a local application to execute arbitrary code on the target system.
The vulnerability exists due to a boundary error within the OS kernel. A malicious application can trigger memory corruption and execute arbitrary code on the target system.
Note, the vulnerability is being actively exploited in the wild.
Affected software
iPadOS
Apple iOS
visionOS
watchOS
macOS
tvOS
Apple iOS
visionOS
watchOS
macOS
tvOS
How to mitigate CVE-2024-23225
Install updates from vendor's website.
iPadOS - addressed in versions 16.7.6, 17.4 21E217
Apple iOS - addressed in versions 16.7.6 20H320, 17.4 21E217
visionOS - update to 1.1
watchOS - update to 10.4
macOS - addressed in versions 12.7.4 21H1123, 13.6.5 22G621, 14.4 23E214
tvOS - update to 17.4
Apple iOS - addressed in versions 16.7.6 20H320, 17.4 21E217
visionOS - update to 1.1
watchOS - update to 10.4
macOS - addressed in versions 12.7.4 21H1123, 13.6.5 22G621, 14.4 23E214
tvOS - update to 17.4
External References
Related Security Bulletins
- Multiple vulnerabilities in Apple iOS 16 and iPadOS 16
- Multiple vulnerabilities in Apple iOS 17 and iPadOS 17
- Multiple vulnerabilities in Apple macOS Monterey
- Multiple vulnerabilities in Apple macOS Ventura
- Multiple vulnerabilities in Apple macOS Sonoma
- Multiple vulnerabilities in Apple tvOS
- Multiple vulnerabilities in Apple watchOS
- Multiple vulnerabilities in Apple visionOS