CVE-2024-23265

Published Mar 8, 2024

Last updated 2 months ago

CVSS high 7.8
Apple
macOS

Overview

AI description

Automated description summarized from trusted sources.

CVE-2024-23265 is a memory corruption vulnerability that was addressed by improving locking mechanisms. This vulnerability affects multiple Apple operating systems, including macOS Monterey, macOS Ventura, macOS Sonoma, visionOS, iOS, iPadOS, watchOS, and tvOS. Successful exploitation of this vulnerability could allow an application to cause unexpected system termination or enable the writing of arbitrary kernel memory. It was addressed by adding locking and guards, which prevents the return of a potentially poisoned or invalid pointer.

Description
A memory corruption vulnerability was addressed with improved locking. This issue is fixed in iOS 16.7.6 and iPadOS 16.7.6, iOS 17.4 and iPadOS 17.4, macOS Monterey 12.7.4, macOS Sonoma 14.4, macOS Ventura 13.6.5, tvOS 17.4, visionOS 1.1, watchOS 10.4. An app may be able to cause unexpected system termination or write kernel memory.
Source
product-security@apple.com
NVD status
Modified
Products
ipados, iphone_os, macos, tvos, visionos, watchos

Risk scores

CVSS 3.1

Type
Primary
Base score
7.8
Impact score
5.9
Exploitability score
1.8
Vector string
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Severity
HIGH

Weaknesses

nvd@nist.gov
CWE-787
134c704f-9b21-4f2e-91b3-4a467353bcc0
CWE-400

Social media

Hype score
Not currently trending
  1. Top 5 Trending CVEs: 1 - CVE-2026-9082 2 - CVE-2026-9256 3 - CVE-2026-44578 4 - CVE-2026-42897 5 - CVE-2024-23265 #cve #cvetrends #cveshield #cybersecurity https://t.co/4Fua3CAN6W

    @CVEShield

    24 May 2026

    133 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  2. Patch-diffing CVE-2024-23265 in the AppleDiskImages2 KEXT, the entire iOS kernel fix is one added equality check: https://t.co/uVMsogIozK The methodology covers every function in the KEXT. ipsw pulls kernelcaches from iOS 17.3.1 and 17.4, ipsw's symbolicator names the functions,

    @8kSec

    22 May 2026

    2628 Impressions

    11 Retweets

    51 Likes

    26 Bookmarks

    2 Replies

    0 Quotes

  3. A missing lock in a kernel driver is indistinguishable from valid code, until it crashes. We tracked down the fix for CVE-2024-23265 to see how Apple resolved a race condition in AppleDiskImages2. https://t.co/uVMsogIWpi See how we used Ghidra to locate the specific instruction

    @8kSec

    21 Jan 2026

    7084 Impressions

    24 Retweets

    162 Likes

    91 Bookmarks

    0 Replies

    0 Quotes

  4. Patch Diffing CVE-2024-23265: An iOS Kernel Memory Corruption Vulnerability - @8kSec https://t.co/vqMawNrKiv

    @kmkz_security

    23 Oct 2025

    3358 Impressions

    14 Retweets

    53 Likes

    12 Bookmarks

    1 Reply

    0 Quotes

  5. 🚨New blog alert! Patch Diffing CVE-2024-23265: An iOS Kernel Memory Corruption Vulnerability https://t.co/uVMsogIozK by @s3rg0x Today we’re patch diffing CVE-2024-23265, a kernel-level memory corruption vulnerability in iOS. See how we used IPSW, Ghidra, and decompiled diffs

    @8kSec

    8 Oct 2025

    9471 Impressions

    40 Retweets

    141 Likes

    69 Bookmarks

    0 Replies

    1 Quote

  6. 🔴 #macOS Kernel Vulnerability: #CVE-2024-23265 (Critical) https://t.co/Uz096i6tIx

    @dailycve

    9 Dec 2024

    14 Impressions

    1 Retweet

    3 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

Configurations