CVE-2024-23222: Apple Multiple Products WebKit Type Confusion Vulnerability
A type confusion issue was addressed with improved checks. Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been exploited.
Reference: https://webkitgtk.org/security/WSA-2024-0001.html
Other sources
A type confusion issue was addressed with improved checks. This issue is fixed in iOS 17.3 and iPadOS 17.3, macOS Sonoma 14.3, tvOS 17.3. Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been exploited.
— Ubuntu
A type confusion issue was addressed with improved checks. This issue is fixed in Safari 17.3, iOS 15.8.7 and iPadOS 15.8.7, iOS 16.7.5 and iPadOS 16.7.5, iOS 17.3 and iPadOS 17.3, macOS Monterey 12.7.3, macOS Sonoma 14.3, macOS Ventura 13.6.4, tvOS 17.3, visionOS 1.0.2. Processing maliciously crafted web content may lead to arbitrary code execution. This fix associated with the Coruna exploit was shipped in iOS 17.3 on January 22, 2024. This update brings that fix to devices that cannot update to the latest iOS version.
— MITRE
Apple iOS, iPadOS, macOS, tvOS, and Safari WebKit contain a type confusion vulnerability that leads to code execution when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing.
— CISA
Kernel. A use-after-free issue was addressed with improved memory management.
— Apple
WebKit. A type confusion issue was addressed with improved checks.
— Apple
Credit
Affected Software
Remediation
Information
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2024-23212
- CVE-2024-23218
- CVE-2024-23224
- CVE-2024-23208
- CVE-2024-23201
- CVE-2024-23209
- CVE-2024-23207
- CVE-2024-23223
- CVE-2024-27791
- CVE-2024-23211
- CVE-2024-23203
- CVE-2024-23204
- CVE-2024-23217
- CVE-2024-23215
- CVE-2024-23210
- CVE-2024-23206
- CVE-2024-23213
- CVE-2024-23214
- CVE-2024-23222
- CVE-2024-23271
- CVE-2025-24085
- CVE-2023-42937
- CVE-2023-38545
- CVE-2023-38039
- CVE-2023-38546
- CVE-2023-42888
- CVE-2023-40528
- CVE-2023-42935
- CVE-2023-42887
- CVE-2024-23228
- CVE-2024-23219
- CVE-2023-41974
- CVE-2023-43000
- CVE-2023-43010
Frequently Asked Questions
What is the severity of CVE-2024-23222?
CVE-2024-23222 is considered to have a high severity due to the potential for arbitrary code execution.
How do I fix CVE-2024-23222?
To address CVE-2024-23222, users should update to the latest versions of affected products as specified by Apple and other vendors.
What are the affected products for CVE-2024-23222?
CVE-2024-23222 affects various Apple products including iOS, iPadOS, macOS, and Safari, as well as Debian and Ubuntu packages like webkit2gtk and wpewebkit.
Is CVE-2024-23222 being actively exploited?
Yes, there are reports indicating that CVE-2024-23222 may have been exploited in the wild.
What types of vulnerabilities does CVE-2024-23222 involve?
CVE-2024-23222 involves a type confusion vulnerability that can lead to arbitrary code execution when handling malicious web content.