Vulnerability Description
The issue was addressed with improved memory handling. This issue is fixed in iOS 16.7.6 and iPadOS 16.7.6, macOS Monterey 12.7.4, macOS Sonoma 14.4, macOS Ventura 13.6.5, visionOS 1.1. Processing an image may result in disclosure of process memory.
CVSS Score
LOW
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Apple | Ipados | < 16.7.6 |
| Apple | Iphone Os | < 16.7.6 |
| Apple | Macos | >= 12.0, < 12.7.4 |
| Apple | Visionos | < 1.1 |
Related Weaknesses (CWE)
References
- https://support.apple.com/en-us/120880
- https://support.apple.com/en-us/120883
- https://support.apple.com/en-us/120884
- https://support.apple.com/en-us/120886
- https://support.apple.com/en-us/120895
- http://seclists.org/fulldisclosure/2024/Mar/21Mailing ListThird Party Advisory
- http://seclists.org/fulldisclosure/2024/Mar/22Mailing ListThird Party Advisory
- http://seclists.org/fulldisclosure/2024/Mar/23Mailing ListThird Party Advisory
- http://seclists.org/fulldisclosure/2024/Mar/26Mailing ListThird Party Advisory
- https://support.apple.com/en-us/HT214082Vendor Advisory
- https://support.apple.com/en-us/HT214083Vendor Advisory
- https://support.apple.com/en-us/HT214084Vendor Advisory
- https://support.apple.com/en-us/HT214085Vendor Advisory
- https://support.apple.com/en-us/HT214087Vendor Advisory
- https://support.apple.com/kb/HT214082
FAQ
What is CVE-2024-23257?
CVE-2024-23257 is a vulnerability with a CVSS score of 3.3 (LOW). The issue was addressed with improved memory handling. This issue is fixed in iOS 16.7.6 and iPadOS 16.7.6, macOS Monterey 12.7.4, macOS Sonoma 14.4, macOS Ventura 13.6.5, visionOS 1.1. Processing an ...
How severe is CVE-2024-23257?
CVE-2024-23257 has been rated LOW with a CVSS base score of 3.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-23257?
Check the references section above for vendor advisories and patch information. Affected products include: Apple Ipados, Apple Iphone Os, Apple Macos, Apple Visionos.