CVE-2024-23222

Published Jan 23, 2024

Last updated a month ago

Exploit knownCVSS high 8.8
iPadOS
iOS
macOS Sonoma
Mobile device

Overview

AI description

Automated description summarized from trusted sources.

CVE-2024-23222 is a type confusion vulnerability found within WebKit, the browser engine that powers Apple's Safari and all web browsers on iOS and iPadOS. This flaw allows for arbitrary code execution if a user processes maliciously crafted web content. Apple has acknowledged reports indicating that this issue may have been actively exploited. The vulnerability was addressed by Apple with improved checks and was fixed in various operating system updates, including iOS 17.3, iPadOS 17.3, macOS Sonoma 14.3, and tvOS 17.3. It has also been noted as part of the "Coruna" exploit kit, which targeted iOS devices.

Description
A type confusion issue was addressed with improved checks. This issue is fixed in Safari 17.3, iOS 15.8.7 and iPadOS 15.8.7, iOS 16.7.5 and iPadOS 16.7.5, iOS 17.3 and iPadOS 17.3, macOS Monterey 12.7.3, macOS Sonoma 14.3, macOS Ventura 13.6.4, tvOS 17.3, visionOS 1.0.2. Processing maliciously crafted web content may lead to arbitrary code execution. This fix associated with the Coruna exploit was shipped in iOS 17.3 on January 22, 2024. This update brings that fix to devices that cannot update to the latest iOS version.
Source
product-security@apple.com
NVD status
Analyzed
Products
safari, ipados, iphone_os, macos, tvos, visionos

Risk scores

CVSS 3.1

Type
Primary
Base score
8.8
Impact score
5.9
Exploitability score
2.8
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Severity
HIGH

Known exploits

Data from CISA

Vulnerability name
Apple Multiple Products WebKit Type Confusion Vulnerability
Exploit added on
Jan 23, 2024
Exploit action due
Feb 13, 2024
Required action
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Weaknesses

nvd@nist.gov
CWE-843
134c704f-9b21-4f2e-91b3-4a467353bcc0
CWE-843

Social media

Hype score
Not currently trending
  1. NVDでApple関連CVE 200件のメタデータ一斉更新。WebKit型混乱(CVE-2024-23222)やカーネルメモリ破壊(CVE-2024-23225/23296)など悪用確認済み3件含む。古いiOS/macOSを使い続けている場合は改めて確認を。 #セキュリティ #C

    @aisolostudio

    3 Apr 2026

    58 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  2. Attackers are chaining WebKit exploits with sandbox escapes to achieve kernel-level access on iOS devices. TRC analysis shows DarkSword uses CVE-2024-23222 and CVE-2023-32409 for initial compromise, then escalates privileges to exfiltrate passwords and crypto wallets.

    @aviatrixtrc

    18 Mar 2026

    75 Impressions

    0 Retweets

    0 Likes

    1 Bookmark

    0 Replies

    0 Quotes

  3. Top 5 Trending CVEs: 1 - CVE-2024-23222 2 - CVE-2023-41993 3 - CVE-2025-64755 4 - CVE-2025-43300 5 - CVE-2026-3910 #cve #cvetrends #cveshield #cybersecurity https://t.co/4Fua3CAN6W

    @CVEShield

    15 Mar 2026

    342 Impressions

    0 Retweets

    3 Likes

    1 Bookmark

    0 Replies

    0 Quotes

  4. "patched .. underlying vulnerabilities in iOS updates .. over .. 2 years .. fixes for users who cannot update ..latest version. Specifically, iOS and iPadOS 15.8.7 patch 4 vulnerabilities: CVE-2023-41974, CVE-2024-23222, CVE-2023-43000, and CVE-2023-43010" https://t.co/xrdMU89

    @christinayiotis

    14 Mar 2026

    124 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  5. Top 5 Trending CVEs: 1 - CVE-2026-25253 2 - CVE-2024-23222 3 - CVE-2026-3909 4 - CVE-2026-21643 5 - CVE-2026-2636 #cve #cvetrends #cveshield #cybersecurity https://t.co/4Fua3CAN6W

    @CVEShield

    14 Mar 2026

    157 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  6. I am releasing a reconstructed version of the cassowary CVE (CVE-2024-23222) that was disclosed as part of the Coruna leak. I also did some research with my AI assistants 😄 to reproduce a crash for the bug on x86_64 Linux https://t.co/75c7MOTz1a

    @FuzzySec

    13 Mar 2026

    5756 Impressions

    14 Retweets

    62 Likes

    26 Bookmarks

    1 Reply

    0 Quotes

  7. Apple has released security patches for older iPhones and iPads to fix kernel and WebKit vulnerabilities exploited by the Coruna exploit kit, addressing multiple CVEs including CVE-2023-41974 and CVE-2024-23222. #Coruna #ExploitPatch #USA https://t.co/9zTv70oc6r

    @TweetThreatNews

    12 Mar 2026

    215 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  8. Top 5 Trending CVEs: 1 - CVE-2024-23222 2 - CVE-2026-22719 3 - CVE-2026-25611 4 - CVE-2025-38617 5 - CVE-2026-21902 #cve #cvetrends #cveshield #cybersecurity https://t.co/4Fua3CAN6W

    @CVEShield

    5 Mar 2026

    232 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

Configurations