CVE-2024-23296: Apple Multiple Products Memory Corruption Vulnerability
A memory corruption issue was addressed with improved validation. This issue is fixed in iOS 16.7.8 and iPadOS 16.7.8, iOS 17.4 and iPadOS 17.4, macOS Monterey 12.7.6, macOS Sonoma 14.4, macOS Ventura 13.6.7, tvOS 17.4, visionOS 1.1, watchOS 10.4. An attacker with arbitrary kernel read and write capability may be able to bypass kernel memory protections. Apple is aware of a report that this issue may have been exploited.
Other sources
Accessibility. A privacy issue was addressed with improved private data redaction for log entries.
— Apple
Accessibility. This issue was addressed with additional entitlement checks.
— Apple
Admin Framework. A logic issue was addressed with improved checks.
— Apple
Airport. This issue was addressed with improved redaction of sensitive information.
— Apple
APFS. The issue was addressed with improved restriction of data container access.
— Apple
Credit
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Apple macOSto a version that resolves this vulnerability.Fixed in 14.4 - Upgrade
Upgrade
tvOSto a version that resolves this vulnerability.Fixed in 17.4 - Upgrade
Upgrade
Apple iOS, iPadOS, and watchOSto a version that resolves this vulnerability.Fixed in 10.4 - Upgrade
Upgrade
visionOSto a version that resolves this vulnerability.Fixed in 1.1 - Upgrade
Upgrade
macOSto a version that resolves this vulnerability.Fixed in 12.7.6 - Upgrade
Upgrade
macOS Venturato a version that resolves this vulnerability.Fixed in 13.6.7 - Upgrade
Upgrade
Apple iOS and iPadOSto a version that resolves this vulnerability.Fixed in 17.4 - Upgrade
Upgrade
Apple iOS, iPadOS, and macOSto a version that resolves this vulnerability.Fixed in 17.4 - Upgrade
Upgrade
Apple iOS and iPadOSto a version that resolves this vulnerability.Fixed in 16.7.8 - Upgrade
Upgrade
Apple iOS, iPadOS, and macOSto a version that resolves this vulnerability.Fixed in 16.7.8 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 13.6.7 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 17.4 - Upgrade
Upgrade
Apple iOSto a version that resolves this vulnerability.Fixed in 16.7.8 - Upgrade
Upgrade
Apple iOSto a version that resolves this vulnerability.Fixed in 17.4 - Upgrade
Upgrade
Apple iPadOSto a version that resolves this vulnerability.Fixed in 16.7.8 - Upgrade
Upgrade
Apple iPadOSto a version that resolves this vulnerability.Fixed in 17.4 - Upgrade
Upgrade
macOS Montereyto a version that resolves this vulnerability.Fixed in 12.7.6 - Upgrade
Upgrade
macOS Sonomato a version that resolves this vulnerability.Fixed in 14.4 - Upgrade
Upgrade
watchOSto a version that resolves this vulnerability.Fixed in 10.4 - Upgrade
Upgrade
OpenSSHto a version that resolves this vulnerability.Fixed in 9.6
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2024-23225
- CVE-2024-23243
- CVE-2024-23256
- CVE-2024-23291
- CVE-2024-23276
- CVE-2024-23227
- CVE-2024-27886
- CVE-2024-23233
- CVE-2024-23269
- CVE-2024-23288
- CVE-2024-23277
- CVE-2024-23247
- CVE-2024-23248
- CVE-2024-23249
- CVE-2024-23250
- CVE-2024-23299
- CVE-2024-23244
- CVE-2024-23205
- CVE-2022-48554
- CVE-2024-23229
- CVE-2024-27789
- CVE-2024-23253
- CVE-2024-23270
- CVE-2024-23257
- CVE-2024-23258
- CVE-2024-23286
- CVE-2024-23234
- CVE-2024-23266
- CVE-2024-23235
- CVE-2024-23265
- CVE-2024-27853
- CVE-2024-23278
- CVE-2024-0258
- CVE-2024-23279
- CVE-2024-23287
- CVE-2024-23264
- CVE-2024-23285
- CVE-2024-27809
- CVE-2024-23283
- CVE-2024-27887
- CVE-2023-48795
- CVE-2023-51384
- CVE-2023-51385
- CVE-2022-42816
- CVE-2024-23216
- CVE-2024-23267
- CVE-2024-23268
- CVE-2024-23274
- CVE-2023-42853
- CVE-2024-23275
- CVE-2024-27888
- CVE-2024-23255
- CVE-2024-23294
- CVE-2024-23296
- CVE-2024-23259
- CVE-2024-23273
- CVE-2024-23238
- CVE-2024-23239
- CVE-2024-23290
- CVE-2024-23232
- CVE-2024-23231
- CVE-2024-23230
- CVE-2024-23245
- CVE-2024-23292
- CVE-2024-23289
- CVE-2024-23293
- CVE-2024-23241
- CVE-2024-23272
- CVE-2024-23242
- CVE-2024-23281
- CVE-2024-27792
- CVE-2024-23261
- CVE-2024-23260
- CVE-2024-23246
- CVE-2024-23226
- CVE-2024-23254
- CVE-2024-23263
- CVE-2024-23280
- CVE-2024-23284
- CVE-2024-23297
- CVE-2024-54658
- CVE-2024-27859
- CVE-2024-23262
- CVE-2024-23295
- CVE-2024-23220
- CVE-2024-40783
- CVE-2024-27826
- CVE-2024-40775
- CVE-2024-40774
- CVE-2024-27877
- CVE-2024-40799
- CVE-2024-27873
- CVE-2024-2004
- CVE-2024-2379
- CVE-2024-2398
- CVE-2024-2466
- CVE-2024-40827
- CVE-2024-40828
- CVE-2023-6277
- CVE-2023-52356
- CVE-2024-40806
- CVE-2024-40816
- CVE-2024-40788
- CVE-2024-40803
- CVE-2024-40796
- CVE-2024-6387
- CVE-2024-40781
- CVE-2024-40802
- CVE-2024-40823
- CVE-2024-27882
- CVE-2024-27883
- CVE-2024-40800
- CVE-2024-40817
- CVE-2024-27881
- CVE-2024-40821
- CVE-2024-40798
- CVE-2024-40833
- CVE-2024-40835
- CVE-2024-40807
- CVE-2024-40834
- CVE-2024-40787
- CVE-2024-40793
- CVE-2024-40809
- CVE-2024-40812
- CVE-2024-44205
- CVE-2024-27805
- CVE-2024-27817
- CVE-2024-27831
- CVE-2024-27827
- CVE-2024-27799
- CVE-2024-27840
- CVE-2024-27823
- CVE-2023-42861
- CVE-2024-27810
- CVE-2024-27800
- CVE-2024-27802
- CVE-2024-27885
- CVE-2024-27824
- CVE-2024-27843
- CVE-2024-27855
- CVE-2024-27806
- CVE-2024-27798
- CVE-2024-27847
- CVE-2024-27796
- CVE-2024-23240
- CVE-2024-40771
- CVE-2024-27818
- CVE-2024-23251
- CVE-2024-23282
- CVE-2024-27807
- CVE-2024-27856
- CVE-2024-27838
- CVE-2024-27833
- CVE-2024-27834
- CVE-2024-27820
Frequently Asked Questions
What is the severity of CVE-2024-23296?
CVE-2024-23296 is a critical vulnerability due to memory corruption that could allow an attacker to bypass kernel memory protections.
How do I fix CVE-2024-23296?
To fix CVE-2024-23296, users should update their devices to iOS 17.4, iPadOS 17.4, watchOS 10.4, tvOS 17.4, visionOS 1.1, or macOS versions as specified in the vulnerability details.
Which Apple products are affected by CVE-2024-23296?
CVE-2024-23296 affects multiple Apple products including iOS, iPadOS, watchOS, tvOS, and various macOS versions.
What types of attacks could exploit CVE-2024-23296?
CVE-2024-23296 could be exploited by attackers capable of executing arbitrary kernel read and write operations.
Is there a known workaround for CVE-2024-23296?
As of now, a specific workaround for CVE-2024-23296 has not been documented, and updating the software is recommended.