Vulnerability Description
A type confusion issue was addressed with improved checks. This issue is fixed in Safari 17.3, iOS 15.8.7 and iPadOS 15.8.7, iOS 16.7.5 and iPadOS 16.7.5, iOS 17.3 and iPadOS 17.3, macOS Monterey 12.7.3, macOS Sonoma 14.3, macOS Ventura 13.6.4, tvOS 17.3, visionOS 1.0.2. Processing maliciously crafted web content may lead to arbitrary code execution. This fix associated with the Coruna exploit was shipped in iOS 17.3 on January 22, 2024. This update brings that fix to devices that cannot update to the latest iOS version.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Apple | Safari | < 17.3 |
| Apple | Ipados | < 15.8.7 |
| Apple | Iphone Os | < 15.8.7 |
| Apple | Macos | >= 12.0, < 12.7.3 |
| Apple | Tvos | < 17.3 |
| Apple | Visionos | < 1.0.2 |
Related Weaknesses (CWE)
References
- https://support.apple.com/en-us/118479Release NotesVendor Advisory
- https://support.apple.com/en-us/120304Release NotesVendor Advisory
- https://support.apple.com/en-us/120305Release NotesVendor Advisory
- https://support.apple.com/en-us/120307Release NotesVendor Advisory
- https://support.apple.com/en-us/120309Release NotesVendor Advisory
- https://support.apple.com/en-us/120310Release NotesVendor Advisory
- https://support.apple.com/en-us/120311Release NotesVendor Advisory
- https://support.apple.com/en-us/120339Release NotesVendor Advisory
- https://support.apple.com/en-us/126632Release NotesVendor Advisory
- http://seclists.org/fulldisclosure/2024/Feb/6Third Party Advisory
- http://seclists.org/fulldisclosure/2024/Jan/34Third Party Advisory
- http://seclists.org/fulldisclosure/2024/Jan/40Third Party Advisory
- https://lists.fedoraproject.org/archives/list/[email protected]Broken Link
- https://support.apple.com/en-us/HT214055Release NotesVendor Advisory
- https://support.apple.com/en-us/HT214059Release NotesVendor Advisory
FAQ
What is CVE-2024-23222?
CVE-2024-23222 is a vulnerability with a CVSS score of 8.8 (HIGH). A type confusion issue was addressed with improved checks. This issue is fixed in Safari 17.3, iOS 15.8.7 and iPadOS 15.8.7, iOS 16.7.5 and iPadOS 16.7.5, iOS 17.3 and iPadOS 17.3, macOS Monterey 12.7...
How severe is CVE-2024-23222?
CVE-2024-23222 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-23222?
Check the references section above for vendor advisories and patch information. Affected products include: Apple Safari, Apple Ipados, Apple Iphone Os, Apple Macos, Apple Tvos.