EXPOSURES › CVE-2024-23296
CVE-2024-23296
HIGH ⌖ ON CISA KEV · EXPLOITEDApple's RTKit on iOS/macOS allows kernel memory bypass enabling arbitrary code execution.
A memory corruption flaw in Apple's RTKit lets attackers bypass kernel protections to execute arbitrary code, directly threatening DIB endpoints running Apple devices. This is a high-severity, actively exploited vulnerability that requires immediate patching to prevent unauthorized access and potential data exfiltration.
Shame score — Active exploitation of a high-severity memory corruption flaw in widely deployed Apple products poses a severe risk to DIB systems relying on these devices.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Apple iOS, iPadOS, macOS, tvOS, and watchOS RTKit contain a memory corruption vulnerability that allows an attacker with arbitrary kernel read and write capability to bypass kernel memory protections.