CVE-2024-23222
גבוהה 8.8 מנוצלת בשטח (KEV)
ניצול פעיל מאומת — קטלוג CISA KEV
- שם
- Apple Multiple Products WebKit Type Confusion Vulnerability
- נוסף לקטלוג
- יעד טיפול (פדרלי)
- פעולה נדרשת
- Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
תיאור (מקור, אנגלית)
A type confusion issue was addressed with improved checks. This issue is fixed in Safari 17.3, iOS 15.8.7 and iPadOS 15.8.7, iOS 16.7.5 and iPadOS 16.7.5, iOS 17.3 and iPadOS 17.3, macOS Monterey 12.7.3, macOS Sonoma 14.3, macOS Ventura 13.6.4, tvOS 17.3, visionOS 1.0.2. Processing maliciously crafted web content may lead to arbitrary code execution. This fix associated with the Coruna exploit was shipped in iOS 17.3 on January 22, 2024. This update brings that fix to devices that cannot update to the latest iOS version.
מדדים
- CVSS 3.1
-
8.8 (HIGH)
מקור הציון: NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H - EPSS — סבירות ניצול
- 11% (אחוזון 100) נכון ל-25/7/2026
- CWE
- CWE-843
מוצרים מושפעים
apple: safari; apple: ipados; apple: iphone os; apple: macos; apple: tvos; apple: visionos
קישורים
- https://support.apple.com/en-us/118479 Release NotesVendor Advisory
- https://support.apple.com/en-us/120304 Release NotesVendor Advisory
- https://support.apple.com/en-us/120305 Release NotesVendor Advisory
- https://support.apple.com/en-us/120307 Release NotesVendor Advisory
- https://support.apple.com/en-us/120309 Release NotesVendor Advisory
- https://support.apple.com/en-us/120310 Release NotesVendor Advisory
- https://support.apple.com/en-us/120311 Release NotesVendor Advisory
- https://support.apple.com/en-us/120339 Release NotesVendor Advisory
- https://support.apple.com/en-us/126632 Release NotesVendor Advisory
- https://support.apple.com/en-us/HT214055 Release NotesVendor Advisory