CVE-2024-23225: Apple Multiple Products Memory Corruption Vulnerability
A memory corruption issue was addressed with improved validation. This issue is fixed in iOS 16.7.6 and iPadOS 16.7.6, iOS 17.4 and iPadOS 17.4, macOS Monterey 12.7.4, macOS Sonoma 14.4, macOS Ventura 13.6.5, tvOS 17.4, visionOS 1.1, watchOS 10.4. An attacker with arbitrary kernel read and write capability may be able to bypass kernel memory protections. Apple is aware of a report that this issue may have been exploited.
Other sources
Accessibility. A privacy issue was addressed with improved private data redaction for log entries.
— Apple
Accessibility. This issue was addressed with additional entitlement checks.
— Apple
Admin Framework. A logic issue was addressed with improved checks.
— Apple
Airport. This issue was addressed with improved redaction of sensitive information.
— Apple
AppKit. A logic issue was addressed with improved restrictions.
— Apple
Credit
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Apple macOSto a version that resolves this vulnerability.Fixed in 14.4 - Upgrade
Upgrade
tvOSto a version that resolves this vulnerability.Fixed in 17.4 - Upgrade
Upgrade
Apple iOS, iPadOS, and watchOSto a version that resolves this vulnerability.Fixed in 10.4 - Upgrade
Upgrade
visionOSto a version that resolves this vulnerability.Fixed in 1.1 - Upgrade
Upgrade
macOSto a version that resolves this vulnerability.Fixed in 12.7.4 - Upgrade
Upgrade
macOS Venturato a version that resolves this vulnerability.Fixed in 13.6.5 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 13.6.5 - Upgrade
Upgrade
Apple iOS and iPadOSto a version that resolves this vulnerability.Fixed in 17.4 - Upgrade
Upgrade
Apple iOS, iPadOS, and macOSto a version that resolves this vulnerability.Fixed in 17.4 - Upgrade
Upgrade
Apple iOS and iPadOSto a version that resolves this vulnerability.Fixed in 16.7.6 - Upgrade
Upgrade
Apple iOS, iPadOS, and macOSto a version that resolves this vulnerability.Fixed in 16.7.6 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 17.4 - Upgrade
Upgrade
macOS Montereyto a version that resolves this vulnerability.Fixed in 12.7.4 - Upgrade
Upgrade
macOS Sonomato a version that resolves this vulnerability.Fixed in 14.4 - Upgrade
Upgrade
watchOSto a version that resolves this vulnerability.Fixed in 10.4 - Compensating control
Discontinue use of the product if mitigations are unavailable.
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2024-23296
- CVE-2024-23243
- CVE-2024-23256
- CVE-2024-23291
- CVE-2024-23276
- CVE-2024-23227
- CVE-2024-27886
- CVE-2024-23233
- CVE-2024-23269
- CVE-2024-23288
- CVE-2024-23277
- CVE-2024-23247
- CVE-2024-23248
- CVE-2024-23249
- CVE-2024-23250
- CVE-2024-23299
- CVE-2024-23244
- CVE-2024-23205
- CVE-2022-48554
- CVE-2024-23229
- CVE-2024-27789
- CVE-2024-23253
- CVE-2024-23270
- CVE-2024-23257
- CVE-2024-23258
- CVE-2024-23286
- CVE-2024-23234
- CVE-2024-23266
- CVE-2024-23235
- CVE-2024-23265
- CVE-2024-23225
- CVE-2024-27853
- CVE-2024-23278
- CVE-2024-0258
- CVE-2024-23279
- CVE-2024-23287
- CVE-2024-23264
- CVE-2024-23285
- CVE-2024-27809
- CVE-2024-23283
- CVE-2024-27887
- CVE-2023-48795
- CVE-2023-51384
- CVE-2023-51385
- CVE-2022-42816
- CVE-2024-23216
- CVE-2024-23267
- CVE-2024-23268
- CVE-2024-23274
- CVE-2023-42853
- CVE-2024-23275
- CVE-2024-27888
- CVE-2024-23255
- CVE-2024-23294
- CVE-2024-23259
- CVE-2024-23273
- CVE-2024-23238
- CVE-2024-23239
- CVE-2024-23290
- CVE-2024-23232
- CVE-2024-23231
- CVE-2024-23230
- CVE-2024-23245
- CVE-2024-23292
- CVE-2024-23289
- CVE-2024-23293
- CVE-2024-23241
- CVE-2024-23272
- CVE-2024-23242
- CVE-2024-23281
- CVE-2024-27792
- CVE-2024-23261
- CVE-2024-23260
- CVE-2024-23246
- CVE-2024-23226
- CVE-2024-23254
- CVE-2024-23263
- CVE-2024-23280
- CVE-2024-23284
- CVE-2024-23297
- CVE-2024-54658
- CVE-2024-27859
- CVE-2024-23262
- CVE-2024-23295
- CVE-2024-23220
- CVE-2024-23218
- CVE-2024-23201
- CVE-2023-28826
- CVE-2024-23204
- CVE-2023-40389
- CVE-2024-23203
- CVE-2024-23217
- CVE-2024-23240
Frequently Asked Questions
What is the severity of CVE-2024-23225?
CVE-2024-23225 is considered a critical vulnerability due to its potential to bypass kernel memory protections.
How do I fix CVE-2024-23225?
To fix CVE-2024-23225, update your device to the latest version, either iOS 16.7.6, iPadOS 16.7.6, iOS 17.4, or iPadOS 17.4.
What products are affected by CVE-2024-23225?
CVE-2024-23225 affects Apple iOS, iPadOS, watchOS, tvOS, visionOS, and macOS versions specified in the advisory.
Can exploitation of CVE-2024-23225 allow for remote attacks?
Yes, exploitation of CVE-2024-23225 could allow an attacker with kernel read and write capabilities to bypass security protections.
When was CVE-2024-23225 disclosed?
CVE-2024-23225 was disclosed and addressed in updates released by Apple in early 2024.