CVE-2024-23265

Published Mar 8, 2024

Last updated 10 months ago

CVSS high 7.8
Apple
macOS

Overview

AI description

Automated description summarized from trusted sources.

CVE-2024-23265 is a memory corruption vulnerability that was addressed by improving locking mechanisms. This vulnerability affects multiple Apple operating systems, including macOS Monterey, macOS Ventura, macOS Sonoma, visionOS, iOS, iPadOS, watchOS, and tvOS. Successful exploitation of this vulnerability could allow an application to cause unexpected system termination or enable the writing of arbitrary kernel memory. It was addressed by adding locking and guards, which prevents the return of a potentially poisoned or invalid pointer.

Description
A memory corruption vulnerability was addressed with improved locking. This issue is fixed in macOS Monterey 12.7.4, macOS Ventura 13.6.5, macOS Sonoma 14.4, visionOS 1.1, iOS 17.4 and iPadOS 17.4, watchOS 10.4, iOS 16.7.6 and iPadOS 16.7.6, tvOS 17.4. An app may be able to cause unexpected system termination or write kernel memory.
Source
product-security@apple.com
NVD status
Analyzed
Products
ipados, iphone_os, macos, tvos, visionos, watchos

Risk scores

CVSS 3.1

Type
Primary
Base score
7.8
Impact score
5.9
Exploitability score
1.8
Vector string
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Severity
HIGH

Weaknesses

nvd@nist.gov
CWE-787
134c704f-9b21-4f2e-91b3-4a467353bcc0
CWE-400

Social media

Hype score is a measure of social media activity compared against trending CVEs from the past 12 months. Max score 100.

Hype score

19

Configurations