CVE-2024-23218
A timing side-channel issue was addressed with improvements to constant-time computation in cryptographic functions. This issue is fixed in iOS 16.7.6 and iPadOS 16.7.6, iOS 17.3 and iPadOS 17.3, macOS Monterey 12.7.4, macOS Sonoma 14.3, macOS Ventura 13.6.5, tvOS 17.3, watchOS 10.3. An attacker may be able to decrypt legacy RSA PKCS#1 v1.5 ciphertexts without having the private key.
Credit
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-23218?
CVE-2024-23218 has a moderate severity level due to its potential to allow attackers to decrypt certain RSA ciphertexts.
How do I fix CVE-2024-23218?
To mitigate CVE-2024-23218, update your device to the latest versions of macOS Sonoma 14.3, watchOS 10.3, tvOS 17.3, iOS 17.3, or iPadOS 17.3.
Which products are affected by CVE-2024-23218?
CVE-2024-23218 affects Apple products including iOS 16.7.6 and 17.3, iPadOS 16.7.6 and 17.3, macOS Monterey 12.7.4, macOS Ventura 13.6.5, tvOS 17.3, and watchOS 10.3.
What type of vulnerability is CVE-2024-23218?
CVE-2024-23218 is characterized as a timing side-channel vulnerability impacting cryptographic function implementations.
Can legacy RSA PKCS#1 v1.5 ciphertexts be attacked due to CVE-2024-23218?
Yes, CVE-2024-23218 may allow an attacker to decrypt legacy RSA PKCS#1 v1.5 ciphertexts under specific conditions.