Apple Multiple Products Memory Corruption Vulnerability
Summary
| CVE | CVE-2024-23225 |
|---|---|
| State | PUBLISHED |
| Assigner | Unknown |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2024-03-05 20:16:00 UTC |
| Updated | 2024-03-19 01:00:00 UTC |
| Description | Apple iOS, iPadOS, macOS, tvOS, watchOS, and visionOS kernel contain a memory corruption vulnerability that allows an attacker with arbitrary kernel read and write capability to bypass kernel memory protections. |
Risk And Classification
EPSS: 0.001560000 probability, percentile 0.363410000 (date 2026-04-01)
CISA KEV: Listed on 2024-03-06; due 2024-03-27; ransomware use Unknown
Problem Types: CWE-787
CISA Known Exploited Vulnerability
| Vendor | Apple |
|---|---|
| Product | Multiple Products |
| Name | Apple Multiple Products Memory Corruption Vulnerability |
| Required Action | Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. |
| Notes | https://support.apple.com/en-us/HT214081, https://support.apple.com/en-us/HT214082, https://support.apple.com/en-us/HT214083, https://support.apple.com/en-us/HT214084, https://support.apple.com/en-us/HT214085, https://support.apple.com/en-us/HT214086, https://support.apple.com/en-us/HT214087, https://support.apple.com/en-us/HT214088 ; https://nvd.nist.gov/vuln/detail/CVE-2024-23225 |
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Apple | Ipad Os | All | All | All | All |
| Operating System | Apple | Iphone Os | All | All | All | All |
| Operating System | Apple | Macos | All | All | All | All |
| Operating System | Apple | Tvos | All | All | All | All |
| Operating System | Apple | Visionos | All | All | All | All |
| Operating System | Apple | Watchos | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| seclists.org/fulldisclosure/2024/Mar/18 | seclists.org | ||
| seclists.org/fulldisclosure/2024/Mar/26 | seclists.org | ||
| seclists.org/fulldisclosure/2024/Mar/22 | seclists.org | ||
| support.apple.com/en-us/HT214081 | support.apple.com | ||
| seclists.org/fulldisclosure/2024/Mar/23 | seclists.org | ||
| support.apple.com/kb/HT214086 | support.apple.com | Vendor Advisory | |
| seclists.org/fulldisclosure/2024/Mar/19 | seclists.org | ||
| support.apple.com/kb/HT214084 | support.apple.com | Vendor Advisory | |
| seclists.org/fulldisclosure/2024/Mar/24 | seclists.org | ||
| support.apple.com/en-us/HT214082 | support.apple.com | ||
| seclists.org/fulldisclosure/2024/Mar/21 | seclists.org | ||
| support.apple.com/kb/HT214088 | support.apple.com | Vendor Advisory | |
| seclists.org/fulldisclosure/2024/Mar/25 | seclists.org | ||
| support.apple.com/kb/HT214083 | support.apple.com | Vendor Advisory | |
| support.apple.com/kb/HT214085 | support.apple.com | Vendor Advisory | |
| support.apple.com/kb/HT214087 | support.apple.com | Vendor Advisory | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
| CISA Known Exploited Vulnerabilities catalog | CISA | www.cisa.gov | kev |
No vendor comments have been submitted for this CVE.