Skip to content
COOEY

EXPOSURES › CVE-2024-23225

CVE-2024-23225

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2024-03-06 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2024-23225 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 85/100 exploited-in-wildunpatchedransomware

Apple's iOS/macOS kernels contain a memory corruption vulnerability allowing arbitrary kernel read/write access, enabling attackers to bypass kernel protections.

This vulnerability allows attackers to bypass kernel memory protections on Apple devices running iOS, iPadOS, macOS, tvOS, watchOS, and visionOS, potentially leading to remote code execution. DIB organizations must ensure all Apple hardware is patched immediately to prevent unauthorized access to sensitive data and maintain NIST 800-171 compliance.

Shame score — A high-severity memory corruption vulnerability in widely used Apple products that allows arbitrary kernel read/write access, posing significant risk to DIB organizations relying on Apple hardware for security controls.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Apple iOS, iPadOS, macOS, tvOS, watchOS, and visionOS kernel contain a memory corruption vulnerability that allows an attacker with arbitrary kernel read and write capability to bypass kernel memory protections.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.