CVE-2024-23222: Apple Multiple Products WebKit Type Confusion Vulnerability
A type confusion issue was addressed with improved checks. Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been exploited.
Reference: https://webkitgtk.org/security/WSA-2024-0001.html
Other sources
A type confusion issue was addressed with improved checks. This issue is fixed in iOS 17.3 and iPadOS 17.3, macOS Sonoma 14.3, tvOS 17.3. Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been exploited.
— Ubuntu
A type confusion issue was addressed with improved checks. This issue is fixed in Safari 17.3, iOS 15.8.7 and iPadOS 15.8.7, iOS 16.7.5 and iPadOS 16.7.5, iOS 17.3 and iPadOS 17.3, macOS Monterey 12.7.3, macOS Sonoma 14.3, macOS Ventura 13.6.4, tvOS 17.3, visionOS 1.0.2. Processing maliciously crafted web content may lead to arbitrary code execution. This fix associated with the Coruna exploit was shipped in iOS 17.3 on January 22, 2024. This update brings that fix to devices that cannot update to the latest iOS version.
— MITRE
Apple iOS, iPadOS, macOS, tvOS, and Safari WebKit contain a type confusion vulnerability that leads to code execution when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing.
— CISA
Kernel. A use-after-free issue was addressed with improved memory management.
— Apple
WebKit. A type confusion issue was addressed with improved checks.
— Apple
Credit
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/webkit2gtkto a version that resolves this vulnerability.Fixed in 2.42.5-1~deb11u1Fixed in 2.42.5-1~deb12u1Fixed in 2.42.5-1Fixed in 2.44.1-1 - Upgrade
Upgrade
debian/wpewebkitto a version that resolves this vulnerability.Fixed in 2.42.5-1Fixed in 2.44.1-1 - Upgrade
Upgrade
ubuntu/webkit2gtkto a version that resolves this vulnerability.Fixed in 2.42.5-0ubuntu0.22.04.2 - Upgrade
Upgrade
ubuntu/webkit2gtkto a version that resolves this vulnerability.Fixed in 2.42.5-0ubuntu0.23.10.2 - Upgrade
Upgrade
ubuntu/webkit2gtkto a version that resolves this vulnerability.Fixed in 2.42.5 - Upgrade
Upgrade
Apple macOSto a version that resolves this vulnerability.Fixed in 14.3 - Upgrade
Upgrade
tvOSto a version that resolves this vulnerability.Fixed in 17.3 - Upgrade
Upgrade
visionOSto a version that resolves this vulnerability.Fixed in 1.0.2 - Upgrade
Upgrade
macOSto a version that resolves this vulnerability.Fixed in 12.7.3 - Upgrade
Upgrade
macOS Venturato a version that resolves this vulnerability.Fixed in 13.6.4 - Upgrade
Upgrade
Safarito a version that resolves this vulnerability.Fixed in 17.3 - Upgrade
Upgrade
Apple iOS and iPadOSto a version that resolves this vulnerability.Fixed in 17.3 - Upgrade
Upgrade
Apple iOS, iPadOS, and macOSto a version that resolves this vulnerability.Fixed in 17.3 - Upgrade
Upgrade
Apple iOS and iPadOSto a version that resolves this vulnerability.Fixed in 16.7.5 - Upgrade
Upgrade
Apple iOS, iPadOS, and macOSto a version that resolves this vulnerability.Fixed in 16.7.5 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 15.8.7 - Upgrade
Upgrade
Apple iOSto a version that resolves this vulnerability.Fixed in 17.3 - Upgrade
Upgrade
Apple iPadOSto a version that resolves this vulnerability.Fixed in 17.3 - Upgrade
Upgrade
Apple macOSto a version that resolves this vulnerability.Fixed in Sonoma 14.3 - Upgrade
Upgrade
Apple tvOSto a version that resolves this vulnerability.Fixed in 17.3 - Operational
Apply mitigations per vendor instructions for any affected devices that cannot update; discontinue use of the product if mitigations are unavailable.
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2024-23212
- CVE-2024-23218
- CVE-2024-23224
- CVE-2024-23208
- CVE-2024-23201
- CVE-2024-23209
- CVE-2024-23207
- CVE-2024-23223
- CVE-2024-27791
- CVE-2024-23211
- CVE-2024-23203
- CVE-2024-23204
- CVE-2024-23217
- CVE-2024-23215
- CVE-2024-23210
- CVE-2024-23206
- CVE-2024-23213
- CVE-2024-23214
- CVE-2024-23222
- CVE-2024-23271
- CVE-2025-24085
- CVE-2023-42937
- CVE-2023-38545
- CVE-2023-38039
- CVE-2023-38546
- CVE-2023-42888
- CVE-2023-40528
- CVE-2023-42935
- CVE-2023-42887
- CVE-2024-23228
- CVE-2024-23219
- CVE-2023-41974
- CVE-2023-43000
- CVE-2023-43010
Frequently Asked Questions
What is the severity of CVE-2024-23222?
CVE-2024-23222 is considered to have a high severity due to the potential for arbitrary code execution.
How do I fix CVE-2024-23222?
To address CVE-2024-23222, users should update to the latest versions of affected products as specified by Apple and other vendors.
What are the affected products for CVE-2024-23222?
CVE-2024-23222 affects various Apple products including iOS, iPadOS, macOS, and Safari, as well as Debian and Ubuntu packages like webkit2gtk and wpewebkit.
Is CVE-2024-23222 being actively exploited?
Yes, there are reports indicating that CVE-2024-23222 may have been exploited in the wild.
What types of vulnerabilities does CVE-2024-23222 involve?
CVE-2024-23222 involves a type confusion vulnerability that can lead to arbitrary code execution when handling malicious web content.