Skip to content
COOEY

EXPOSURES › CVE-2024-23222

CVE-2024-23222

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2024-01-23 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2024-23222 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 45/100 rceexploited-in-wildransomwaresupply-chain

Apple WebKit type confusion vulnerability enables remote code execution via malicious web content on iOS, macOS, and Safari.

This vulnerability allows attackers to execute arbitrary code by crafting malicious web content, posing a significant risk to DIB organizations relying on Apple devices or browsers for sensitive data. The active exploitation status and remote code execution capability necessitate immediate patching and network segmentation to prevent unauthorized access to classified systems.

Shame score — While not a zero-day, the active exploitation status and broad impact on critical Apple products used in defense applications warrant a moderate embarrassment score.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Apple iOS, iPadOS, macOS, tvOS, and Safari WebKit contain a type confusion vulnerability that leads to code execution when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.