Threat Advisory

Apple Addresses Zero-Day Vulnerability Impacting Apple Devices

Threat: Vulnerability
Criticality: High
[subscribe_to_unlock_form]

Summary:

A critical zero-day vulnerability, identified as CVE-2024-23222, has been discovered in Apple's ecosystem, affecting iOS, macOS, tvOS, Safari, and potentially exposing iPhones, Macs, and Apple TVs to exploitation. Tracked as a WebKit confusion issue, attackers could leverage this vulnerability to achieve code execution on targeted devices by enticing users to visit a malicious web page. Successful exploitation grants threat actors the ability to execute arbitrary malicious code, posing a severe security risk to devices running vulnerable iOS, macOS, and tvOS versions. The extensive list of impacted devices spans various iPhone and iPad models, as well as Macs running macOS Monterey and later, and all Apple TV models. While Apple is aware of in-the-wild exploitation, specific details about these attacks have not been disclosed. Users are strongly advised to promptly install the provided security updates to mitigate the risk of potential targeted attacks leveraging this zero-day vulnerability.[/subscribe_to_unlock_form]

Summary:

A critical zero-day vulnerability, identified as CVE-2024-23222, has been discovered in Apple's ecosystem, affecting iOS, macOS, tvOS, Safari, and potentially exposing iPhones, Macs, and Apple TVs to exploitation. Tracked as a WebKit confusion issue, attackers could leverage this vulnerability to achieve code execution on targeted devices by enticing users to visit a malicious web page. Successful exploitation grants threat actors the ability to execute arbitrary malicious code, posing a severe security risk to devices running vulnerable iOS, macOS, and tvOS versions. The extensive list of impacted devices spans various iPhone and iPad models, as well as Macs running macOS Monterey and later, and all Apple TV models. While Apple is aware of in-the-wild exploitation, specific details about these attacks have not been disclosed. Users are strongly advised to promptly install the provided security updates to mitigate the risk of potential targeted attacks leveraging this zero-day vulnerability.[emaillocker id="1283"]

Recommendations:

  • We strongly recommend you upgrade to macOS Sonoma 14.3, macOS Ventura 13.6.4, Safari 17.3, macOS Ventura 13.6.4, macOS Monterey 12.7.3, tvOS 17.3, iOS 17.3 and iPadOS 17.3, iOS 16.7.5 and iPadOS 16.7.5.

References:

The following reports contain further technical details:

https://www.bleepingcomputer.com/news/apple/apple-fixes-first-zero-day-bug-exploited-in-attacks-this-year/

[/emaillocker]
crossmenu