CVE-2024-23213 is a critical vulnerability affecting Apple's iOS, iPadOS, macOS, tvOS, watchOS, and Safari, where processing malicious web content can lead to arbitrary code execution due to improved memory handling issues. With a CVSS score of 8.8 (HIGH), it is a network-exploitable vulnerability requiring user interaction, allowing for high impact on confidentiality, integrity, and availability. While no active exploitation, public exploits, or Metasploit/Nuclei modules are currently available, and community discussion is minimal, the high severity warrants prompt patching. Apple has released fixes in watchOS 10.3, tvOS 17.3, iOS 17.3 and iPadOS 17.3, macOS Sonoma 14.3, iOS 16.7.5 and iPadOS 16.7.5, and Safari 17.3.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 17.3CPE matchmatch criteria | cpe:2.3:a:apple:safari:*:*:*:*:*:*:*:* | ||
> 16.0, < 16.7.5CPE matchmatch criteria | cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:* | ||
> 17.0, < 17.3CPE matchmatch criteria | cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:* | ||
> 16.0, < 16.7.5CPE matchmatch criteria | cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:* | ||
> 17.0, < 17.3CPE matchmatch criteria | cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.