CVE-2024-23269
Published Mar 7, 2024
·Updated
A downgrade issue affecting Intel-based Mac computers was addressed with additional code-signing restrictions. This issue is fixed in macOS Monterey 12.7.4, macOS Sonoma 14.4, macOS Ventura 13.6.5. An app may be able to modify protected parts of the file system.
Credit
Mickey Jin@@patch1t, Wojciech Regula(SecuRing), Kirin@@Pwnrin, Marc Newlin(SkySafe), m4yfly with TianGong Team(Legendsec at Qi'anxin Group), Guilherme Rambo(Best Buddy Apps), an anonymous researcher, Csaba Fitzl@@theevilbit(OffSec), CVE-2024-23205, CVE-2022-48554, Joshua Jewett@@JoshJewett33, Junsung Lee(Trend Micro Zero Day Initiative), Zhenjiang Zhao(pangu team), Qianxin(CrowdStrike Counter Adversary Operations), (CrowdStrike Counter Adversary Operations), Amir Bazine(CrowdStrike Counter Adversary Operations), Karsten König(CrowdStrike Counter Adversary Operations), Dohyun Lee@@l33d0hyun, Lyutoon, Mr.R, Murray Mike, Pedro Tôrres@@t0rr3sp3dr0, CVE-2024-23235, Xinru Chi(Pangu Lab), CVE-2024-23225, koocola, ali yabuz, Meysam Firouzi@@R00tkitsmm(Trend Micro Zero Day Initiative), @@08Tc3wBB(Jamf), CVE-2024-23283, CVE-2023-48795, CVE-2023-51384, CVE-2023-51385, Bohdan Stasiuk@@Bohdan_Stasiuk, Harsh Tyagi, CVE-2024-23296, Lyra Rebane (rebane2001), Matej Rabzelj, CVE-2024-23238, Yiğit Can YILMAZ@@yilmazcanyigit, luckyu@@uuulucky, K宝(Fudan University), LFY@@secsys(Fudan University), Lewis Hardy, Bistrit Dahal, CVE-2024-23241, CVE-2024-23242, Matthew Loewen, Deutsche Telekom Security GmbH sponsored by Bundesamt für Sicherheit in der Informationstechnik, anbu1024(SecANT), Pwn2car, James Lee@@Windowsrcer, Johan Carlsson (joaxcar), Georg Felber, Marco Squarcina, Brian McNulty, Stephan Casas, CVE-2024-23291, Clemens Lang, Koh M. Nakagawa(FFRI Security Inc), Meng Zhang (鲸落)(NorthSea), Jubaer Alnazi@@h33tjubaer, Csaba Fitzl@@theevilbit(Offensive Security)
Affected Software
6 affected componentsFixes available
apple macOS Sonoma<14.4
14.4
apple macOS Monterey<12.7.4
12.7.4
apple macOS Ventura<13.6.5
13.6.5
Apple macOS>=12.0<12.7.4
Apple macOS>=13.0<13.6.5
Apple macOS>=14.0<14.4
Event History
Mar 7, 2024
Data Sourced
via Apple·12:00 AM
DescriptionWeaknessAffected Software
Updated
via Apple·12:00 AM
DescriptionWeakness
Mar 8, 2024
CVE Published
via MITRE·01:35 AM
Data Sourced
via MITRE·01:35 AM
DescriptionWeakness
Data Sourced
via NVD·02:15 AM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-23269?
CVE-2024-23269 is categorized as a moderate severity vulnerability affecting Intel-based Mac computers.
2
How do I fix CVE-2024-23269?
To resolve CVE-2024-23269, update your macOS to version 12.7.4, 13.6.5, or 14.4.
3
What systems are affected by CVE-2024-23269?
CVE-2024-23269 impacts macOS versions prior to 12.7.4, 13.6.5, and 14.4.
4
What type of issue is CVE-2024-23269?
CVE-2024-23269 is a downgrade vulnerability that may allow an app to modify protected parts of the file system.
5
Is CVE-2024-23269 a remote exploitation vulnerability?
CVE-2024-23269 does not appear to be remotely exploitable as it requires local access to the affected system.