CVE-2024-23213: Buffer Overflow
Apple Neural Engine. The issue was addressed with improved memory handling.
Other sources
CoreCrypto. A timing side-channel issue was addressed with improvements to constant-time computation in cryptographic functions.
— Apple
Kernel. The issue was addressed with improved memory handling.
— Apple
libxpc. A permissions issue was addressed with additional restrictions.
— Apple
Mail Search. This issue was addressed with improved redaction of sensitive information.
— Apple
NSSpellChecker. A privacy issue was addressed with improved handling of files.
— Apple
Credit
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/webkit2gtkto a version that resolves this vulnerability.Fixed in 2.42.5-1~deb11u1Fixed in 2.42.5-1~deb12u1Fixed in 2.42.5-1Fixed in 2.44.1-1 - Upgrade
Upgrade
debian/wpewebkitto a version that resolves this vulnerability.Fixed in 2.42.5-1Fixed in 2.44.1-1 - Upgrade
Upgrade
ubuntu/webkit2gtkto a version that resolves this vulnerability.Fixed in 2.42.5-0ubuntu0.22.04.2 - Upgrade
Upgrade
ubuntu/webkit2gtkto a version that resolves this vulnerability.Fixed in 2.42.5-0ubuntu0.23.10.2 - Upgrade
Upgrade
ubuntu/webkit2gtkto a version that resolves this vulnerability.Fixed in 2.42.5 - Upgrade
Upgrade
Apple macOSto a version that resolves this vulnerability.Fixed in 14.3 - Upgrade
Upgrade
tvOSto a version that resolves this vulnerability.Fixed in 17.3 - Upgrade
Upgrade
Apple iOS, iPadOS, and watchOSto a version that resolves this vulnerability.Fixed in 10.3 - Upgrade
Upgrade
Safarito a version that resolves this vulnerability.Fixed in 17.3 - Upgrade
Upgrade
Apple iOS and iPadOSto a version that resolves this vulnerability.Fixed in 17.3 - Upgrade
Upgrade
Apple iOS, iPadOS, and macOSto a version that resolves this vulnerability.Fixed in 17.3 - Upgrade
Upgrade
Apple iOS and iPadOSto a version that resolves this vulnerability.Fixed in 16.7.5 - Upgrade
Upgrade
Apple iOS, iPadOS, and macOSto a version that resolves this vulnerability.Fixed in 16.7.5 - Upgrade
Upgrade
iOSto a version that resolves this vulnerability.Fixed in 16.7.5 - Upgrade
Upgrade
iPadOSto a version that resolves this vulnerability.Fixed in 16.7.5 - Upgrade
Upgrade
iOSto a version that resolves this vulnerability.Fixed in 17.3 - Upgrade
Upgrade
iPadOSto a version that resolves this vulnerability.Fixed in 17.3 - Upgrade
Upgrade
macOS Sonomato a version that resolves this vulnerability.Fixed in 14.3 - Upgrade
Upgrade
watchOSto a version that resolves this vulnerability.Fixed in 10.3
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2024-23212
- CVE-2024-23218
- CVE-2024-23224
- CVE-2024-23208
- CVE-2024-23201
- CVE-2024-23209
- CVE-2024-23207
- CVE-2024-23223
- CVE-2024-27791
- CVE-2024-23211
- CVE-2024-23203
- CVE-2024-23204
- CVE-2024-23217
- CVE-2024-23215
- CVE-2024-23210
- CVE-2024-23206
- CVE-2024-23213
- CVE-2024-23214
- CVE-2024-23222
- CVE-2024-23271
- CVE-2024-23228
- CVE-2024-23219
- CVE-2023-42937
- CVE-2023-42888
Frequently Asked Questions
What is the severity of CVE-2024-23213?
CVE-2024-23213 has been rated as high severity due to its potential exploitability and impact on affected software.
How do I fix CVE-2024-23213?
To fix CVE-2024-23213, update the affected software to the latest patched versions as specified in the remediation.
Which software is affected by CVE-2024-23213?
CVE-2024-23213 affects multiple software products, including Safari, macOS Sonoma, iOS, iPadOS, watchOS, and specific versions of WebKit and WPE WebKit.
What type of vulnerability is CVE-2024-23213?
CVE-2024-23213 is a timing side-channel vulnerability related to improper memory handling and constant-time computation in cryptographic functions.
How can I verify if I am affected by CVE-2024-23213?
You can verify if you are affected by CVE-2024-23213 by checking if your version of the impacted software matches any of the versions listed in the vulnerability report.