Race condition in macOS - CVE-2024-23235

 

Race condition in macOS - CVE-2024-23235

Published: March 7, 2024


Vulnerability identifier: #VU87251
CSH Severity: Low
CVSS v4 BT: 5.9 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear]
CVE-ID: CVE-2024-23235
CWE-ID: CWE-362
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local application to escalate privileges on the system.

The vulnerability exists due to a race condition within the OS kernel. A local application can exploit the race and gain unauthorized access to sensitive information and escalate privileges on the system.


Affected software

macOS
visionOS
watchOS
iPadOS
Apple iOS
tvOS

How to mitigate CVE-2024-23235

Install updates from vendor's website.

macOS - update to 14.4 23E214
visionOS - update to 1.1
watchOS - update to 10.4
iPadOS - addressed in versions 16.7.6, 17.4 21E217
Apple iOS - addressed in versions 16.7.6 20H320, 17.4 21E217
tvOS - update to 17.4

External References

Related Security Bulletins