CVE-2024-23222
Published Jan 23, 2024
Last updated a month ago
AI description
CVE-2024-23222 is a type confusion vulnerability found within WebKit, the browser engine that powers Apple's Safari and all web browsers on iOS and iPadOS. This flaw allows for arbitrary code execution if a user processes maliciously crafted web content. Apple has acknowledged reports indicating that this issue may have been actively exploited. The vulnerability was addressed by Apple with improved checks and was fixed in various operating system updates, including iOS 17.3, iPadOS 17.3, macOS Sonoma 14.3, and tvOS 17.3. It has also been noted as part of the "Coruna" exploit kit, which targeted iOS devices.
- Description
- A type confusion issue was addressed with improved checks. This issue is fixed in Safari 17.3, iOS 15.8.7 and iPadOS 15.8.7, iOS 16.7.5 and iPadOS 16.7.5, iOS 17.3 and iPadOS 17.3, macOS Monterey 12.7.3, macOS Sonoma 14.3, macOS Ventura 13.6.4, tvOS 17.3, visionOS 1.0.2. Processing maliciously crafted web content may lead to arbitrary code execution. This fix associated with the Coruna exploit was shipped in iOS 17.3 on January 22, 2024. This update brings that fix to devices that cannot update to the latest iOS version.
- Source
- product-security@apple.com
- NVD status
- Analyzed
- Products
- safari, ipados, iphone_os, macos, tvos, visionos
CVSS 3.1
- Type
- Primary
- Base score
- 8.8
- Impact score
- 5.9
- Exploitability score
- 2.8
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
- Severity
- HIGH
Data from CISA
- Vulnerability name
- Apple Multiple Products WebKit Type Confusion Vulnerability
- Exploit added on
- Jan 23, 2024
- Exploit action due
- Feb 13, 2024
- Required action
- Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
- Hype score
- Not currently trending
NVDでApple関連CVE 200件のメタデータ一斉更新。WebKit型混乱(CVE-2024-23222)やカーネルメモリ破壊(CVE-2024-23225/23296)など悪用確認済み3件含む。古いiOS/macOSを使い続けている場合は改めて確認を。 #セキュリティ #C
@aisolostudio
3 Apr 2026
58 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Attackers are chaining WebKit exploits with sandbox escapes to achieve kernel-level access on iOS devices. TRC analysis shows DarkSword uses CVE-2024-23222 and CVE-2023-32409 for initial compromise, then escalates privileges to exfiltrate passwords and crypto wallets.
@aviatrixtrc
18 Mar 2026
75 Impressions
0 Retweets
0 Likes
1 Bookmark
0 Replies
0 Quotes
Top 5 Trending CVEs: 1 - CVE-2024-23222 2 - CVE-2023-41993 3 - CVE-2025-64755 4 - CVE-2025-43300 5 - CVE-2026-3910 #cve #cvetrends #cveshield #cybersecurity https://t.co/4Fua3CAN6W
@CVEShield
15 Mar 2026
342 Impressions
0 Retweets
3 Likes
1 Bookmark
0 Replies
0 Quotes
"patched .. underlying vulnerabilities in iOS updates .. over .. 2 years .. fixes for users who cannot update ..latest version. Specifically, iOS and iPadOS 15.8.7 patch 4 vulnerabilities: CVE-2023-41974, CVE-2024-23222, CVE-2023-43000, and CVE-2023-43010" https://t.co/xrdMU89
@christinayiotis
14 Mar 2026
124 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Top 5 Trending CVEs: 1 - CVE-2026-25253 2 - CVE-2024-23222 3 - CVE-2026-3909 4 - CVE-2026-21643 5 - CVE-2026-2636 #cve #cvetrends #cveshield #cybersecurity https://t.co/4Fua3CAN6W
@CVEShield
14 Mar 2026
157 Impressions
0 Retweets
1 Like
0 Bookmarks
0 Replies
0 Quotes
I am releasing a reconstructed version of the cassowary CVE (CVE-2024-23222) that was disclosed as part of the Coruna leak. I also did some research with my AI assistants 😄 to reproduce a crash for the bug on x86_64 Linux https://t.co/75c7MOTz1a
@FuzzySec
13 Mar 2026
5756 Impressions
14 Retweets
62 Likes
26 Bookmarks
1 Reply
0 Quotes
Apple has released security patches for older iPhones and iPads to fix kernel and WebKit vulnerabilities exploited by the Coruna exploit kit, addressing multiple CVEs including CVE-2023-41974 and CVE-2024-23222. #Coruna #ExploitPatch #USA https://t.co/9zTv70oc6r
@TweetThreatNews
12 Mar 2026
215 Impressions
0 Retweets
1 Like
0 Bookmarks
0 Replies
0 Quotes
Top 5 Trending CVEs: 1 - CVE-2024-23222 2 - CVE-2026-22719 3 - CVE-2026-25611 4 - CVE-2025-38617 5 - CVE-2026-21902 #cve #cvetrends #cveshield #cybersecurity https://t.co/4Fua3CAN6W
@CVEShield
5 Mar 2026
232 Impressions
0 Retweets
1 Like
0 Bookmarks
0 Replies
0 Quotes
[
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:apple:safari:*:*:*:*:*:*:*:*",
"matchCriteriaId": "3D6F41D4-58ED-4E0B-90B4-3EDDB7CEA240",
"versionEndExcluding": "17.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*",
"matchCriteriaId": "1E574928-4E49-45B0-AE6E-DF4D38897F67",
"versionEndExcluding": "15.8.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*",
"matchCriteriaId": "6C754C13-F742-4697-8E03-277B0D762C61",
"versionEndExcluding": "16.7.5",
"versionStartIncluding": "16.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*",
"matchCriteriaId": "7DFDDBEC-015C-4AC6-A2B8-387839CEDCCE",
"versionEndExcluding": "17.3",
"versionStartIncluding": "17.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*",
"matchCriteriaId": "D1E9DC1A-618A-4CAF-96C7-EC5BA2C1F617",
"versionEndExcluding": "15.8.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*",
"matchCriteriaId": "51A161C8-A96D-48C5-8E8E-180DFF5A6F48",
"versionEndExcluding": "16.7.5",
"versionStartIncluding": "16.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*",
"matchCriteriaId": "FD699999-B0F0-41D0-AE33-E7E4AA3C0F90",
"versionEndExcluding": "17.3",
"versionStartIncluding": "17.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*",
"matchCriteriaId": "ECD0F581-7DA4-428A-A1F5-C9A86DDD99D7",
"versionEndExcluding": "12.7.3",
"versionStartIncluding": "12.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*",
"matchCriteriaId": "A3916CD8-E6D5-4786-903E-B86026859CE6",
"versionEndExcluding": "13.6.4",
"versionStartIncluding": "13.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*",
"matchCriteriaId": "79ADFEBE-99EE-4F01-9AE8-489EB41885D1",
"versionEndExcluding": "14.3",
"versionStartIncluding": "14.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:apple:tvos:*:*:*:*:*:*:*:*",
"matchCriteriaId": "921307BF-8419-42C7-9B2C-8DD643723E38",
"versionEndExcluding": "17.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:apple:visionos:*:*:*:*:*:*:*:*",
"matchCriteriaId": "192B29EB-3DC2-48B9-BA87-50033A2CFF01",
"versionEndExcluding": "1.0.2",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
]