Buffer overflow in iPadOS and Apple iOS - CVE-2024-23225

 

Buffer overflow in iPadOS and Apple iOS - CVE-2024-23225

Published: March 5, 2024


Vulnerability identifier: #VU87134
CSH Severity: High
CVSS v4 BT: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:A/U:Amber]
CVE-ID: CVE-2024-23225
CWE-ID: CWE-119
Exploitation vector: Local access
Exploit availability: The vulnerability is being exploited in the wild

Vulnerability details

The vulnerability allows a local application to execute arbitrary code on the target system.

The vulnerability exists due to a boundary error within the OS kernel. A malicious application can trigger memory corruption and execute arbitrary code on the target system.

Note, the vulnerability is being actively exploited in the wild.


Affected software

iPadOS
Apple iOS
visionOS
watchOS
macOS
tvOS

How to mitigate CVE-2024-23225

Install updates from vendor's website.

iPadOS - addressed in versions 16.7.6, 17.4 21E217
Apple iOS - addressed in versions 16.7.6 20H320, 17.4 21E217
visionOS - update to 1.1
watchOS - update to 10.4
macOS - addressed in versions 12.7.4 21H1123, 13.6.5 22G621, 14.4 23E214
tvOS - update to 17.4

External References

Related Security Bulletins