Junglewise Threat Intelligence

CVE-2024-23222: Apple Multiple Products WebKit Type Confusion Vulnerability

CVE-2024-23222 · Severity: critical · CVSS 8.8 · Exploited in the wild · Published 2024-01-23

Technologies: Apple macOS Monterey, Apple Tvos, Apple Safari, Apple macOS Sonoma, Apple macOS Ventura, Apple Multiple Products, Apple Visionos. Vendors: Apple.

Executive brief

A type confusion vulnerability in Apple's WebKit engine allows for arbitrary code execution when processing maliciously crafted web content. The issue was addressed with improved checks across multiple Apple operating systems and the Safari browser.

Affected products

  • Apple WebKit
  • Apple Safari < 17.3
  • Apple iOS and iPadOS < 15.8.7, 16.x < 16.7.5, 17.x < 17.3
  • Apple macOS Monterey < 12.7.3
  • Apple macOS Ventura < 13.6.4
  • Apple macOS Sonoma < 14.3
  • Apple tvOS < 17.3
  • Apple visionOS < 1.0.2

Timeline

  • 2024-01-22: patched: Initial fix shipped in iOS 17.3
  • 2024-01-23: disclosed
  • 2024-01-23: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2024-01-23: exploited: Reported as exploited in the wild at time of publication

Related threats