CVE-2024-23218: Medium severity Apple macOS Sonoma vulnerability
A timing side-channel issue was addressed with improvements to constant-time computation in cryptographic functions. This issue is fixed in iOS 16.7.6 and iPadOS 16.7.6, iOS 17.3 and iPadOS 17.3, macOS Monterey 12.7.4, macOS Sonoma 14.3, macOS Ventura 13.6.5, tvOS 17.3, watchOS 10.3. An attacker may be able to decrypt legacy RSA PKCS#1 v1.5 ciphertexts without having the private key.
Other sources
Accessibility. This issue was addressed with additional entitlement checks.
— Apple
Admin Framework. A logic issue was addressed with improved checks.
— Apple
Airport. This issue was addressed with improved redaction of sensitive information.
— Apple
Apple Neural Engine. The issue was addressed with improved memory handling.
— Apple
AppleMobileFileIntegrity. A downgrade issue affecting Intel-based Mac computers was addressed with additional code-signing restrictions.
— Apple
Credit
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Apple macOSto a version that resolves this vulnerability.Fixed in 14.3 - Upgrade
Upgrade
tvOSto a version that resolves this vulnerability.Fixed in 17.3 - Upgrade
Upgrade
Apple iOS, iPadOS, and watchOSto a version that resolves this vulnerability.Fixed in 10.3 - Upgrade
Upgrade
macOSto a version that resolves this vulnerability.Fixed in 12.7.4 - Upgrade
Upgrade
macOS Venturato a version that resolves this vulnerability.Fixed in 13.6.5 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 13.6.5 - Upgrade
Upgrade
Apple iOS and iPadOSto a version that resolves this vulnerability.Fixed in 16.7.6 - Upgrade
Upgrade
Apple iOS, iPadOS, and macOSto a version that resolves this vulnerability.Fixed in 16.7.6 - Upgrade
Upgrade
Apple iOS and iPadOSto a version that resolves this vulnerability.Fixed in 17.3 - Upgrade
Upgrade
Apple iOS, iPadOS, and macOSto a version that resolves this vulnerability.Fixed in 17.3 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.7.6 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 17.3 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 12.7.4 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 14.3 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.3
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2024-23212
- CVE-2024-23218
- CVE-2024-23224
- CVE-2024-23208
- CVE-2024-23201
- CVE-2024-23209
- CVE-2024-23207
- CVE-2024-23223
- CVE-2024-27791
- CVE-2024-23211
- CVE-2024-23203
- CVE-2024-23204
- CVE-2024-23217
- CVE-2024-23215
- CVE-2024-23210
- CVE-2024-23206
- CVE-2024-23213
- CVE-2024-23214
- CVE-2024-23222
- CVE-2024-23271
- CVE-2024-23276
- CVE-2024-23227
- CVE-2024-23269
- CVE-2024-23247
- CVE-2024-23299
- CVE-2024-23244
- CVE-2024-23270
- CVE-2024-23286
- CVE-2024-23257
- CVE-2024-23234
- CVE-2024-23266
- CVE-2024-23265
- CVE-2024-23225
- CVE-2023-28826
- CVE-2024-23264
- CVE-2024-23283
- CVE-2024-23274
- CVE-2024-23268
- CVE-2024-23275
- CVE-2024-23267
- CVE-2024-23216
- CVE-2024-23230
- CVE-2024-23245
- CVE-2024-23272
- CVE-2023-40389
- CVE-2024-23229
- CVE-2024-23278
- CVE-2024-23231
- CVE-2024-23262
- CVE-2024-23235
- CVE-2024-23259
- CVE-2024-23289
- CVE-2024-23246
- CVE-2024-23284
- CVE-2024-23263
- CVE-2024-23228
- CVE-2024-23219
Frequently Asked Questions
What is the severity of CVE-2024-23218?
CVE-2024-23218 has a moderate severity level due to its potential to allow attackers to decrypt certain RSA ciphertexts.
How do I fix CVE-2024-23218?
To mitigate CVE-2024-23218, update your device to the latest versions of macOS Sonoma 14.3, watchOS 10.3, tvOS 17.3, iOS 17.3, or iPadOS 17.3.
Which products are affected by CVE-2024-23218?
CVE-2024-23218 affects Apple products including iOS 16.7.6 and 17.3, iPadOS 16.7.6 and 17.3, macOS Monterey 12.7.4, macOS Ventura 13.6.5, tvOS 17.3, and watchOS 10.3.
What type of vulnerability is CVE-2024-23218?
CVE-2024-23218 is characterized as a timing side-channel vulnerability impacting cryptographic function implementations.
Can legacy RSA PKCS#1 v1.5 ciphertexts be attacked due to CVE-2024-23218?
Yes, CVE-2024-23218 may allow an attacker to decrypt legacy RSA PKCS#1 v1.5 ciphertexts under specific conditions.