Executive brief
A memory corruption vulnerability in Apple RTKit allows an attacker with arbitrary kernel read and write capabilities to bypass kernel memory protections. The issue was addressed through improved validation across multiple Apple operating systems.
Affected products
- Apple iOS before 16.7.8, before 17.4
- Apple iPadOS before 16.7.8, before 17.4
- Apple macOS Monterey before 12.7.6
- Apple macOS Sonoma before 14.4
- Apple macOS Ventura before 13.6.7
- Apple tvOS before 17.4
- Apple visionOS before 1.1
- Apple watchOS before 10.4
Timeline
- 2024-03-06: disclosed
- 2024-03-06: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2024-03-06: exploited: Apple is aware of reports that this issue may have been exploited in the wild.