CVE-2024-23296

Confirmed PUBLISHED

A memory corruption issue was addressed with improved validation. This issue is fixed in iOS 16.7.8 and iPadOS 16.7.8, iOS 17.4 and iPadOS 17.4,...

Apple · iOS and iPadOS, macOS, tvOS, visionOS, watchOS
Exploited in the wild

Recommended Action

Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.

Confidence
Confirmed
Exploitation Status
Exploited in the wild
Observed in Sensors
No
Attempts (30d)
Unique Attacker IPs
CISA KEV
In CISA KEV
CVSS / EPSS
7.8 High

At a Glance

A memory corruption issue was addressed with improved validation. This issue is fixed in iOS 16.7.8 and iPadOS 16.7.8, iOS 17.4 and iPadOS 17.4, macOS Monterey 12.7.6, macOS Sonoma 14.4, macOS Ventura 13.6.7, tvOS 17.4, visionOS 1.1, watchOS 10.4. An attacker with arbitrary kernel read and write capability may be able to bypass kernel memory protections. Apple is aware of a report that this issue may have been exploited.

nessus_scanner ios cisa
CVE Published
Mar 05, 2024
Exploitation Reported
Mar 06, 2024
CVSS
7.8 High
EPSS
Low complexity No user interaction

Affected Versions

Vendor Product Version Status
apple
ipad_os

0 to < 17.4

Affected
apple
iphone_os

0 to < 17.4

Affected
apple
macos

14.0 to < 14.4

Affected
apple
tvos

0 to < 17.4

Affected
apple
visionos

0 to < 1.1

Affected
apple
watchos

0 to < 10.4

Affected
Apple
iOS and iPadOS

0 to < 16.7.8

Affected
Apple
iOS and iPadOS

0 to < 17.4

Affected
Apple
macOS

0 to < 12.7.6

Affected
Apple
macOS

0 to < 13.6.7

Affected
Apple
macOS

0 to < 14.4

Affected
Apple
tvOS

0 to < 17.4

Affected
Apple
visionOS

0 to < 1.1

Affected
Apple
watchOS

0 to < 10.4

Affected

CVE References

Show 3 more references

Recommended Actions

  • Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.
  • Check enrichment artifacts for scanner coverage and available PoCs before rolling remediation validation.
  • Use the Pro API to automate enrichment, telemetry, and workflow delivery for VM, SOC, and CTI pipelines.