Apple Multiple Products WebKit Type Confusion Vulnerability
Summary
| CVE | CVE-2024-23222 |
|---|---|
| State | PUBLISHED |
| Assigner | Unknown |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2024-01-23 01:15:00 UTC |
| Updated | 2024-02-06 02:15:00 UTC |
| Description | Apple iOS, iPadOS, macOS, tvOS, and Safari WebKit contain a type confusion vulnerability that leads to code execution when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing. |
Risk And Classification
EPSS: 0.006230000 probability, percentile 0.700640000 (date 2026-04-01)
CISA KEV: Listed on 2024-01-23; due 2024-02-13; ransomware use Unknown
Problem Types: CWE-843
CISA Known Exploited Vulnerability
| Vendor | Apple |
|---|---|
| Product | Multiple Products |
| Name | Apple Multiple Products WebKit Type Confusion Vulnerability |
| Required Action | Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. |
| Notes | https://support.apple.com/en-us/HT214055, https://support.apple.com/en-us/HT214056, https://support.apple.com/en-us/HT214057, https://support.apple.com/en-us/HT214058, https://support.apple.com/en-us/HT214059, https://support.apple.com/en-us/HT214061, https://support.apple.com/en-us/HT214063 ; https://nvd.nist.gov/vuln/detail/CVE-2024-23222 |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| seclists.org/fulldisclosure/2024/Jan/27 | seclists.org | Third Party Advisory | |
| Full Disclosure: APPLE-SA-02-02-2024-1 visionOS 1.0.2 | seclists.org | ||
| support.apple.com/en-us/HT214055 | support.apple.com | Release Notes, Vendor Advisory | |
| support.apple.com/en-us/HT214056 | support.apple.com | Release Notes, Vendor Advisory | |
| support.apple.com/en-us/HT214057 | support.apple.com | Release Notes, Vendor Advisory | |
| Full Disclosure: APPLE-SA-01-22-2024-9 tvOS 17.3 | seclists.org | Third Party Advisory | |
| oss-security - WebKitGTK and WPE WebKit Security Advisory WSA-2024-0001 | www.openwall.com | ||
| Full Disclosure: APPLE-SA-01-22-2024-5 macOS Sonoma 14.3 | seclists.org | Third Party Advisory | |
| seclists.org/fulldisclosure/2024/Jan/37 | seclists.org | Third Party Advisory | |
| seclists.org/fulldisclosure/2024/Jan/33 | seclists.org | Third Party Advisory | |
| support.apple.com/en-us/HT214063 | support.apple.com | Release Notes, Vendor Advisory | |
| support.apple.com/en-us/HT214058 | support.apple.com | Release Notes, Vendor Advisory | |
| seclists.org/fulldisclosure/2024/Jan/38 | seclists.org | Third Party Advisory | |
| seclists.org/fulldisclosure/2024/Jan/34 | seclists.org | Third Party Advisory | |
| support.apple.com/en-us/HT214059 | support.apple.com | Release Notes, Vendor Advisory | |
| support.apple.com/en-us/HT214061 | support.apple.com | Release Notes, Vendor Advisory | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
| CISA Known Exploited Vulnerabilities catalog | CISA | www.cisa.gov | kev |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 200105 Ubuntu Security Notification for WebKitGTK Vulnerabilities (USN-6631-1)
- 284906 Fedora Security Update for webkitgtk (FEDORA-2024-ca3f071aea)
- 284994 Fedora Security Update for webkitgtk (FEDORA-2024-97faaca23d)
- 357104 Amazon Linux Security Advisory for webkitgtk4 : ALAS2-2024-2434
- 379297 Apple Safari Multiple Vulnerabilities (HT214056)
- 379298 Apple macOS Ventura 13.6.4 Not Installed (HT214058)
- 379299 Apple macOS Sonoma 14.3 Not Installed (HT214061)
- 379300 Apple macOS Monterey 12.7.3 Not Installed (HT214057)
- 6000472 Debian Security Update for webkit2gtk (DSA 5618-1)
- 610538 Apple iOS 17.3 and iPadOS 17.3 Security Update Missing (HT214059)
- 610539 Apple iOS 16.7.5 and iPadOS 16.7.5 Security Update Missing (HT214063)
- 755687 SUSE Enterprise Linux Security Update for webkit2gtk3 (SUSE-SU-2024:0301-1)
- 755770 SUSE Enterprise Linux Security Update for webkit2gtk3 (SUSE-SU-2024:0519-1)
- 755789 SUSE Enterprise Linux Security Update for webkit2gtk3 (SUSE-SU-2024:0545-1)
- 755802 SUSE Enterprise Linux Security Update for webkit2gtk3 (SUSE-SU-2024:0548-1)