Buffer overflow in iPadOS and Apple iOS - CVE-2024-23296

 

Buffer overflow in iPadOS and Apple iOS - CVE-2024-23296

Published: March 5, 2024


Vulnerability identifier: #VU87136
CSH Severity: High
CVSS v4 BT: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:A/U:Amber]
CVE-ID: CVE-2024-23296
CWE-ID: CWE-119
Exploitation vector: Local access
Exploit availability: The vulnerability is being exploited in the wild

Vulnerability details

The vulnerability allows a local application to execute arbitrary code on the target system.

The vulnerability exists due to a boundary error in RTKit. A malicious application can trigger memory corruption and execute arbitrary code on the target system.

Note, the vulnerability is being actively exploited in the wild.


Affected software

iPadOS
Apple iOS
visionOS
watchOS
macOS
tvOS

How to mitigate CVE-2024-23296

Install updates from vendor's website.

iPadOS - addressed in versions 17.4 21E217, 16.7.8
Apple iOS - addressed in versions 17.4 21E217, 16.7.8 20H343
visionOS - update to 1.1
watchOS - update to 10.4
macOS - addressed in versions 12.7.6 21H1320, 13.6.7 22G720, 14.4 23E214
tvOS - update to 17.4

External References

Related Security Bulletins