EXPOSURES › CVE-2024-23222
CVE-2024-23222
HIGH ⌖ ON CISA KEV · EXPLOITEDApple WebKit type confusion vulnerability enables remote code execution via malicious web content on iOS, macOS, and Safari.
This vulnerability allows attackers to execute arbitrary code by crafting malicious web content, posing a significant risk to DIB organizations relying on Apple devices or browsers for sensitive data. The active exploitation status and remote code execution capability necessitate immediate patching and network segmentation to prevent unauthorized access to classified systems.
Shame score — While not a zero-day, the active exploitation status and broad impact on critical Apple products used in defense applications warrant a moderate embarrassment score.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Apple iOS, iPadOS, macOS, tvOS, and Safari WebKit contain a type confusion vulnerability that leads to code execution when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing.