Advisories
visionOSExploitedCISA KEV listedCRITICAL2024-03-05
A memory corruption issue was addressed with improved validation. This issue is fixed in iOS 16.7.6 and iPadOS 16.7.6, iOS 17.4 and iPadOS 17.4, macOS Monterey 12.7.4, macOS Sonoma 14.4, macOS Ventura 13.6.5, tvOS 17.4, visionOS 1.1, watchOS 10.4. An a...
CVEs:CVE-2024-23225
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| ipados |
affected |
apple |
— |
— |
| iphone_os |
affected |
apple |
— |
— |
| macos |
affected |
apple |
— |
— |
| tvos |
affected |
apple |
— |
— |
| visionos |
affected |
apple |
— |
— |
| watchos |
affected |
apple |
— |
— |
visionOSExploitedCISA KEV listedCRITICAL2024-03-05
A memory corruption issue was addressed with improved validation. This issue is fixed in iOS 16.7.8 and iPadOS 16.7.8, iOS 17.4 and iPadOS 17.4, macOS Monterey 12.7.6, macOS Sonoma 14.4, macOS Ventura 13.6.7, tvOS 17.4, visionOS 1.1, watchOS 10.4. An a...
CVEs:CVE-2024-23296
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| ipados |
affected |
apple |
— |
— |
| iphone_os |
affected |
apple |
— |
— |
| macos |
affected |
apple |
— |
— |
| tvos |
affected |
apple |
— |
— |
| visionos |
affected |
apple |
— |
— |
| watchos |
affected |
apple |
— |
— |
iPadOSActive exploitation (sightings)MEDIUM2024-03-05
A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in iOS 17.4 and iPadOS 17.4. An app may be able to read sensitive location information.
CVEs:CVE-2024-23243
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| ipad_os |
affected |
apple |
— |
— |
| iphone_os |
affected |
apple |
— |
— |
XcodeActive exploitation (sightings)MEDIUM2024-03-15
A logic issue was addressed with improved state management. This issue is fixed in Xcode 15.3. An app may bypass Gatekeeper checks.
CVEs:CVE-2024-23298
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| xcode |
affected |
apple |
— |
— |
visionOSActive exploitation (sightings)MEDIUM2024-03-07
This issue was addressed with additional entitlement checks. This issue is fixed in iOS 16.7.6 and iPadOS 16.7.6, iOS 17.4 and iPadOS 17.4, visionOS 1.1. An app may be able to spoof system notifications and UI.
CVEs:CVE-2024-23262
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| ipados |
affected |
apple |
— |
— |
| iphone_os |
affected |
apple |
— |
— |
| visionos |
affected |
apple |
— |
— |
OtherActive exploitation (sightings)CRITICAL2024-03-12
A use-after-free issue was addressed with improved memory management. This issue is fixed in GarageBand 10.4.11. Processing a maliciously crafted file may lead to unexpected app termination or arbitrary code execution.
CVEs:CVE-2024-23300
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| garageband |
affected |
apple |
— |
— |
iPadOSActive exploitation (sightings)LOW2024-03-05
A logic issue was addressed with improved state management. This issue is fixed in iOS 17.4 and iPadOS 17.4. A user's locked tabs may be briefly visible while switching tab groups when Locked Private Browsing is enabled.
CVEs:CVE-2024-23256
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| ipad_os |
affected |
apple |
— |
— |
| iphone_os |
affected |
apple |
— |
— |
iPadOSActive exploitation (sightings)LOW2024-03-07
The issue was addressed with improved checks. This issue is fixed in iOS 17.4 and iPadOS 17.4. Shake-to-undo may allow a deleted photo to be re-surfaced without authentication.
CVEs:CVE-2024-23240
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| ipad_os |
affected |
apple |
— |
— |
| iphone_os |
affected |
apple |
— |
— |
OtherPoC exploitHIGH2024-03-26
When an application tells libcurl it wants to allow HTTP/2 server push, and the amount of received headers for the push surpasses the maximum allowed limit (1000), libcurl aborts the server push. When aborting, libcurl inadvertently does not free all t...
CVEs:CVE-2024-2398
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| macos |
affected |
apple |
— |
— |
OtherPoC exploitMEDIUM2024-03-26
libcurl skips the certificate verification for a QUIC connection under certain conditions, when built to use wolfSSL. If told to use an unknown/bad cipher or curve, the error path accidentally skips the verification and returns OK, thus ignoring any ce...
CVEs:CVE-2024-2379
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| macos |
affected |
apple |
— |
— |
OtherPoC exploitLOW2024-03-26
When a protocol selection parameter option disables all protocols without adding any then the default set of protocols would remain in the allowed set due to an error in the logic for removing protocols. The below command would perform a request to cur...
CVEs:CVE-2024-2004
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| macos |
affected |
apple |
— |
— |
visionOSPoC exploitCRITICAL2024-03-07
A logic issue was addressed with improved validation. This issue is fixed in Safari 17.4, iOS 16.7.6 and iPadOS 16.7.6, iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4, tvOS 17.4, visionOS 1.1, watchOS 10.4. Processing maliciously crafted web content may p...
CVEs:CVE-2024-23263
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| ipados |
affected |
apple |
— |
— |
| iphone_os |
affected |
apple |
— |
— |
| macos |
affected |
apple |
— |
— |
| safari |
affected |
apple |
— |
— |
| tvos |
affected |
apple |
— |
— |
| visionos |
affected |
apple |
— |
— |
| watchos |
affected |
apple |
— |
— |
visionOSPoC exploitCRITICAL2024-03-07
A logic issue was addressed with improved state management. This issue is fixed in Safari 17.4, iOS 16.7.6 and iPadOS 16.7.6, iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4, tvOS 17.4, visionOS 1.1, watchOS 10.4. Processing maliciously crafted web content...
CVEs:CVE-2024-23284
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| ipados |
affected |
apple |
— |
— |
| iphone_os |
affected |
apple |
— |
— |
| macos |
affected |
apple |
— |
— |
| safari |
affected |
apple |
— |
— |
| tvos |
affected |
apple |
— |
— |
| visionos |
affected |
apple |
— |
— |
| watchos |
affected |
apple |
— |
— |
OtherPoC exploitMEDIUM2024-03-26
libcurl did not check the server certificate of TLS connections done to a host specified as an IP address, when built to use mbedTLS. libcurl would wrongly avoid using the set hostname function when the specified hostname was given as an IP address, t...
CVEs:CVE-2024-2466
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| macos |
affected |
apple |
— |
— |
iPadOSPoC exploitHIGH2024-03-07
An injection issue was addressed with improved validation. This issue is fixed in Safari 17.4, iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4, tvOS 17.4, watchOS 10.4. A maliciously crafted webpage may be able to fingerprint the user.
CVEs:CVE-2024-23280
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| ipad_os |
affected |
apple |
— |
— |
| iphone_os |
affected |
apple |
— |
— |
| macos |
affected |
apple |
— |
— |
| safari |
affected |
apple |
— |
— |
| tvos |
affected |
apple |
— |
— |
| watchos |
affected |
apple |
— |
— |
visionOSPoC exploitMEDIUM2024-03-07
The issue was addressed with improved UI handling. This issue is fixed in Safari 17.4, iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4, tvOS 17.4, visionOS 1.1, watchOS 10.4. A malicious website may exfiltrate audio data cross-origin.
CVEs:CVE-2024-23254
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| ipad_os |
affected |
apple |
— |
— |
| iphone_os |
affected |
apple |
— |
— |
| macos |
affected |
apple |
— |
— |
| safari |
affected |
apple |
— |
— |
| tvos |
affected |
apple |
— |
— |
| visionos |
affected |
apple |
— |
— |
| watchos |
affected |
apple |
— |
— |
visionOSPoC exploitCRITICAL2024-03-07
A buffer overflow issue was addressed with improved memory handling. This issue is fixed in iOS 16.7.6 and iPadOS 16.7.6, iOS 17.4 and iPadOS 17.4, macOS Monterey 12.7.4, macOS Sonoma 14.4, macOS Ventura 13.6.5, tvOS 17.4, visionOS 1.1, watchOS 10.4. P...
CVEs:CVE-2024-23286
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| ipados |
affected |
apple |
— |
— |
| iphone_os |
affected |
apple |
— |
— |
| macos |
affected |
apple |
— |
— |
| tvos |
affected |
apple |
— |
— |
| visionos |
affected |
apple |
— |
— |
| watchos |
affected |
apple |
— |
— |
iPadOSPoC exploitHIGH2024-03-07
The issue was addressed with improved checks. This issue is fixed in iOS 16.7.6 and iPadOS 16.7.6, iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4. Processing web content may lead to a denial-of-service.
CVEs:CVE-2024-23259
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| ipados |
affected |
apple |
— |
— |
| iphone_os |
affected |
apple |
— |
— |
| macos |
affected |
apple |
— |
— |
visionOSPoC exploitMEDIUM2024-03-07
A validation issue was addressed with improved input sanitization. This issue is fixed in iOS 16.7.6 and iPadOS 16.7.6, iOS 17.4 and iPadOS 17.4, macOS Monterey 12.7.4, macOS Sonoma 14.4, macOS Ventura 13.6.5, tvOS 17.4, visionOS 1.1. An application ma...
CVEs:CVE-2024-23264
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| ipados |
affected |
apple |
— |
— |
| iphone_os |
affected |
apple |
— |
— |
| macos |
affected |
apple |
— |
— |
| tvos |
affected |
apple |
— |
— |
| visionos |
affected |
apple |
— |
— |
iPadOSPoC exploitMEDIUM2024-03-07
This issue was addressed through improved state management. This issue is fixed in Safari 17.4, iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4. Private Browsing tabs may be accessed without authentication.
CVEs:CVE-2024-23273
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| ipad_os |
affected |
apple |
— |
— |
| iphone_os |
affected |
apple |
— |
— |
| macos |
affected |
apple |
— |
— |
| safari |
affected |
apple |
— |
— |
visionOSPoC exploitCRITICAL2024-03-07
A memory corruption vulnerability was addressed with improved locking. This issue is fixed in iOS 16.7.6 and iPadOS 16.7.6, iOS 17.4 and iPadOS 17.4, macOS Monterey 12.7.4, macOS Sonoma 14.4, macOS Ventura 13.6.5, tvOS 17.4, visionOS 1.1, watchOS 10.4....
CVEs:CVE-2024-23265
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| ipados |
affected |
apple |
— |
— |
| iphone_os |
affected |
apple |
— |
— |
| macos |
affected |
apple |
— |
— |
| tvos |
affected |
apple |
— |
— |
| visionos |
affected |
apple |
— |
— |
| watchos |
affected |
apple |
— |
— |
iPadOSPoC exploitMEDIUM2024-03-07
The issue was addressed with improved checks. This issue is fixed in iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4. An attacker in a privileged network position may be able to inject keystrokes by spoofing a keyboard.
CVEs:CVE-2024-23277
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| ipad_os |
affected |
apple |
— |
— |
| iphone_os |
affected |
apple |
— |
— |
| macos |
affected |
apple |
— |
— |
visionOSPoC exploitHIGH2024-03-07
This issue was addressed by removing the vulnerable code. This issue is fixed in iOS 16.7.6 and iPadOS 16.7.6, iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4, tvOS 17.4, visionOS 1.1, watchOS 10.4. An app may be able to break out of its sandbox.
CVEs:CVE-2024-23246
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| ipados |
affected |
apple |
— |
— |
| iphone_os |
affected |
apple |
— |
— |
| macos |
affected |
apple |
— |
— |
| tvos |
affected |
apple |
— |
— |
| visionos |
affected |
apple |
— |
— |
| watchos |
affected |
apple |
— |
— |
iPadOSPoC exploitHIGH2024-03-07
A privacy issue was addressed with improved handling of temporary files. This issue is fixed in iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4, watchOS 10.4. An app may be able to access user-sensitive data.
CVEs:CVE-2024-23287
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| ipados |
affected |
apple |
— |
— |
| iphone_os |
affected |
apple |
— |
— |
| macos |
affected |
apple |
— |
— |
| watchos |
affected |
apple |
— |
— |
iPadOSPoC exploitCRITICAL2024-03-07
An authentication issue was addressed with improved state management. This issue is fixed in iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4. Photos in the Hidden Photos Album may be viewed without authentication.
CVEs:CVE-2024-23255
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| ipad_os |
affected |
apple |
— |
— |
| iphone_os |
affected |
apple |
— |
— |
| macos |
affected |
apple |
— |
— |
iPadOSPoC exploitHIGH2024-03-07
A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4, tvOS 17.4, watchOS 10.4. A malicious app may be able to observe user data in log entries related to ...
CVEs:CVE-2024-23291
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| ipados |
affected |
apple |
— |
— |
| iphone_os |
affected |
apple |
— |
— |
| macos |
affected |
apple |
— |
— |
| tvos |
affected |
apple |
— |
— |
| watchos |
affected |
apple |
— |
— |
visionOSPoC exploitCRITICAL2024-03-07
The issue was addressed with improved memory handling. This issue is fixed in iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4, tvOS 17.4, visionOS 1.1, watchOS 10.4. Processing web content may lead to arbitrary code execution.
CVEs:CVE-2024-27859
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| ipados |
affected |
apple |
— |
— |
| iphone_os |
affected |
apple |
— |
— |
| macos |
affected |
apple |
— |
— |
| tvos |
affected |
apple |
— |
— |
| visionos |
affected |
apple |
— |
— |
| watchos |
affected |
apple |
— |
— |
visionOSPoC exploitHIGH2024-03-07
A race condition was addressed with additional validation. This issue is fixed in iOS 16.7.6 and iPadOS 16.7.6, iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4, tvOS 17.4, visionOS 1.1, watchOS 10.4. An app may be able to access user-sensitive data.
CVEs:CVE-2024-23235
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| ipados |
affected |
apple |
— |
— |
| iphone_os |
affected |
apple |
— |
— |
| macos |
affected |
apple |
— |
— |
| tvos |
affected |
apple |
— |
— |
| visionos |
affected |
apple |
— |
— |
| watchos |
affected |
apple |
— |
— |
iPadOSPoC exploitHIGH2024-03-07
A logic issue was addressed with improved restrictions. This issue is fixed in iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4, tvOS 17.4, watchOS 10.4. An app may be able to access user-sensitive data.
CVEs:CVE-2024-23290
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| ipados |
affected |
apple |
— |
— |
| iphone_os |
affected |
apple |
— |
— |
| macos |
affected |
apple |
— |
— |
| tvos |
affected |
apple |
— |
— |
| watchos |
affected |
apple |
— |
— |
iPadOSPoC exploitHIGH2024-03-07
The issue was addressed with improved checks. This issue is fixed in iOS 16.7.6 and iPadOS 16.7.6, iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4, macOS Ventura 13.6.5, tvOS 17.4, watchOS 10.4. An app may be able to break out of its sandbox.
CVEs:CVE-2024-23278
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| ipados |
affected |
apple |
— |
— |
| iphone_os |
affected |
apple |
— |
— |
| macos |
affected |
apple |
— |
— |
| tvos |
affected |
apple |
— |
— |
| watchos |
affected |
apple |
— |
— |
macOSPoC exploitHIGH2024-03-07
The issue was addressed with improved memory handling. This issue is fixed in macOS Sonoma 14.4. Processing a file may lead to a denial-of-service or potentially disclose memory contents.
CVEs:CVE-2024-23248
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| macos |
affected |
apple |
— |
— |
visionOSPoC exploitLOW2024-03-07
The issue was addressed with improved memory handling. This issue is fixed in iOS 16.7.6 and iPadOS 16.7.6, macOS Monterey 12.7.4, macOS Sonoma 14.4, macOS Ventura 13.6.5, visionOS 1.1. Processing an image may result in disclosure of process memory.
CVEs:CVE-2024-23257
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| ipados |
affected |
apple |
— |
— |
| iphone_os |
affected |
apple |
— |
— |
| macos |
affected |
apple |
— |
— |
| visionos |
affected |
apple |
— |
— |
iPadOSPoC exploitMEDIUM2024-03-07
This issue was addressed through improved state management. This issue is fixed in iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4, tvOS 17.4. An app may be able to leak sensitive user information.
CVEs:CVE-2024-23241
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| ipad_os |
affected |
apple |
— |
— |
| iphone_os |
affected |
apple |
— |
— |
| macos |
affected |
apple |
— |
— |
| tvos |
affected |
apple |
— |
— |
macOSPoC exploitCRITICAL2024-03-07
This issue was addressed by adding an additional prompt for user consent. This issue is fixed in macOS Monterey 12.7.4, macOS Sonoma 14.4, macOS Ventura 13.6.5. Third-party shortcuts may use a legacy action from Automator to send events to apps without...
CVEs:CVE-2024-23245
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| macos |
affected |
apple |
— |
— |
iPadOSPoC exploitMEDIUM2024-03-07
A race condition was addressed with improved state handling. This issue is fixed in iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4, tvOS 17.4, watchOS 10.4. An app may be able to leak sensitive user information.
CVEs:CVE-2024-23239
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| ipad_os |
affected |
apple |
— |
— |
| iphone_os |
affected |
apple |
— |
— |
| macos |
affected |
apple |
— |
— |
| tvos |
affected |
apple |
— |
— |
| watchos |
affected |
apple |
— |
— |
macOSPoC exploitHIGH2024-03-07
An injection issue was addressed with improved input validation. This issue is fixed in macOS Monterey 12.7.4, macOS Sonoma 14.4, macOS Ventura 13.6.5. An app may be able to elevate privileges.
CVEs:CVE-2024-23268
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| macos |
affected |
apple |
— |
— |
macOSPoC exploitHIGH2024-03-07
An injection issue was addressed with improved input validation. This issue is fixed in macOS Monterey 12.7.4, macOS Sonoma 14.4, macOS Ventura 13.6.5. An app may be able to elevate privileges.
CVEs:CVE-2024-23274
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| macos |
affected |
apple |
— |
— |
iPadOSPoC exploitMEDIUM2024-03-07
This issue was addressed through improved state management. This issue is fixed in iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4, tvOS 17.4, watchOS 10.4. An attacker with physical access may be able to use Siri to access sensitive user data.
CVEs:CVE-2024-23293
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| ipad_os |
affected |
apple |
— |
— |
| iphone_os |
affected |
apple |
— |
— |
| macos |
affected |
apple |
— |
— |
| tvos |
affected |
apple |
— |
— |
| watchos |
affected |
apple |
— |
— |
macOSPoC exploitHIGH2024-03-07
A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sonoma 14.4. An app may be able to access a user's Photos Library.
CVEs:CVE-2024-23253
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| macos |
affected |
apple |
— |
— |
macOSPoC exploitCRITICAL2024-03-07
The issue was addressed with improved memory handling. This issue is fixed in macOS Monterey 12.7.4, macOS Sonoma 14.4, macOS Ventura 13.6.5. Processing a file may lead to unexpected app termination or arbitrary code execution.
CVEs:CVE-2024-23247
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| macos |
affected |
apple |
— |
— |
iPadOSPoC exploitMEDIUM2024-03-07
A lock screen issue was addressed with improved state management. This issue is fixed in iOS 16.7.6 and iPadOS 16.7.6, iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4, watchOS 10.4. A person with physical access to a device may be able to use Siri to acces...
CVEs:CVE-2024-23289
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| ipados |
affected |
apple |
— |
— |
| iphone_os |
affected |
apple |
— |
— |
| macos |
affected |
apple |
— |
— |
| watchos |
affected |
apple |
— |
— |
macOSPoC exploitHIGH2024-03-07
A logic issue was addressed with improved checks. This issue is fixed in macOS Monterey 12.7.4, macOS Sonoma 14.4, macOS Ventura 13.6.5. An app may be able to elevate privileges.
CVEs:CVE-2024-23276
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| macos |
affected |
apple |
— |
— |
iPadOSPoC exploitMEDIUM2024-03-07
The issue was addressed with improved checks. This issue is fixed in iOS 17.4 and iPadOS 17.4, tvOS 17.4, watchOS 10.4. A malicious application may be able to access private information.
CVEs:CVE-2024-23297
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| ipad_os |
affected |
apple |
— |
— |
| iphone_os |
affected |
apple |
— |
— |
| tvos |
affected |
apple |
— |
— |
| watchos |
affected |
apple |
— |
— |
macOSPoC exploitCRITICAL2024-03-07
This issue was addressed by removing the vulnerable code. This issue is fixed in macOS Sonoma 14.4. Processing malicious input may lead to code execution.
CVEs:CVE-2024-23294
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| macos |
affected |
apple |
— |
— |
iPadOSPoC exploitCRITICAL2024-03-07
The issue was addressed with improved memory handling. This issue is fixed in iOS 17.4 and iPadOS 17.4, macOS Monterey 12.7.4, macOS Sonoma 14.4, macOS Ventura 13.6.5, tvOS 17.4. An app may be able to execute arbitrary code with kernel privileges.
CVEs:CVE-2024-23270
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| ipad_os |
affected |
apple |
— |
— |
| iphone_os |
affected |
apple |
— |
— |
| macos |
affected |
apple |
— |
— |
| tvos |
affected |
apple |
— |
— |
macOSPoC exploitHIGH2024-03-07
A path handling issue was addressed with improved validation. This issue is fixed in macOS Monterey 12.7.4, macOS Sonoma 14.4, macOS Ventura 13.6.5. An app may be able to overwrite arbitrary files.
CVEs:CVE-2024-23216
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| macos |
affected |
apple |
— |
— |
iPadOSPoC exploitHIGH2024-03-07
A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in iOS 16.7.6 and iPadOS 16.7.6, iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4, macOS Ventura 13.6.5, watchOS 10.4. An app may be able to access user-...
CVEs:CVE-2024-23231
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| ipados |
affected |
apple |
— |
— |
| iphone_os |
affected |
apple |
— |
— |
| macos |
affected |
apple |
— |
— |
| watchos |
affected |
apple |
— |
— |
iPadOSPoC exploitHIGH2024-03-07
This issue was addressed by removing the vulnerable code. This issue is fixed in iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4, tvOS 17.4, watchOS 10.4. An app may be able to elevate privileges.
CVEs:CVE-2024-23288
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| ipados |
affected |
apple |
— |
— |
| iphone_os |
affected |
apple |
— |
— |
| macos |
affected |
apple |
— |
— |
| tvos |
affected |
apple |
— |
— |
| watchos |
affected |
apple |
— |
— |
iPadOSPoC exploitCRITICAL2024-03-07
The issue was addressed with improved memory handling. This issue is fixed in iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4, tvOS 17.4, watchOS 10.4. An app may be able to execute arbitrary code out of its sandbox or with certain elevated privileges.
CVEs:CVE-2024-0258
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| ipad_os |
affected |
apple |
— |
— |
| iphone_os |
affected |
apple |
— |
— |
| macos |
affected |
apple |
— |
— |
| tvos |
affected |
apple |
— |
— |
| watchos |
affected |
apple |
— |
— |
iPadOSPoC exploitHIGH2024-03-07
A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in iOS 16.7.6 and iPadOS 16.7.6, macOS Monterey 12.7.4, macOS Sonoma 14.4, macOS Ventura 13.6.5. An app may be able to access user-sensitive data.
CVEs:CVE-2024-23283
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| ipados |
affected |
apple |
— |
— |
| iphone_os |
affected |
apple |
— |
— |
| macos |
affected |
apple |
— |
— |
macOSPoC exploitCRITICAL2024-03-07
An out-of-bounds write issue was addressed with improved input validation. This issue is fixed in macOS Monterey 12.7.4, macOS Sonoma 14.4, macOS Ventura 13.6.5. An app may be able to execute arbitrary code with kernel privileges.
CVEs:CVE-2024-23234
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| macos |
affected |
apple |
— |
— |
iPadOSPoC exploitLOW2024-03-07
This issue was addressed with improved data protection. This issue is fixed in iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4. An app may be able to access information about a user's contacts.
CVEs:CVE-2024-23292
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| ipados |
affected |
apple |
— |
— |
| iphone_os |
affected |
apple |
— |
— |
| macos |
affected |
apple |
— |
— |
iPadOSPoC exploitHIGH2024-03-07
This issue was addressed with improved redaction of sensitive information. This issue is fixed in iOS 16.7.6 and iPadOS 16.7.6, macOS Monterey 12.7.4, macOS Sonoma 14.1, macOS Ventura 13.6.5. An app may be able to access sensitive user data.
CVEs:CVE-2023-28826
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| ipados |
affected |
apple |
— |
— |
| iphone_os |
affected |
apple |
— |
— |
| macos |
affected |
apple |
— |
— |
macOSPoC exploitHIGH2024-03-07
A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in macOS Sonoma 14.4. An app may be able to access user-sensitive data.
CVEs:CVE-2024-23279
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| macos |
affected |
apple |
— |
— |
iPadOSPoC exploitHIGH2024-03-07
A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 17.3 and iPadOS 17.3, macOS Monterey 12.7.4, macOS Sonoma 14.3, macOS Ventura 13.6.5, tvOS 17.3, watchOS 10.3. An app may be able to cause a denial-of-service.
CVEs:CVE-2024-23201
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| ipados |
affected |
apple |
— |
— |
| iphone_os |
affected |
apple |
— |
— |
| macos |
affected |
apple |
— |
— |
| tvos |
affected |
apple |
— |
— |
| watchos |
affected |
apple |
— |
— |
macOSPoC exploitHIGH2024-03-07
This issue was addressed with improved redaction of sensitive information. This issue is fixed in macOS Monterey 12.7.4, macOS Sonoma 14.4, macOS Ventura 13.6.5. An app may be able to read sensitive location information.
CVEs:CVE-2024-23227
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| macos |
affected |
apple |
— |
— |
macOSPoC exploitMEDIUM2024-03-07
A downgrade issue affecting Intel-based Mac computers was addressed with additional code-signing restrictions. This issue is fixed in macOS Monterey 12.7.4, macOS Sonoma 14.4, macOS Ventura 13.6.5. An app may be able to modify protected parts of the fi...
CVEs:CVE-2024-23269
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| macos |
affected |
apple |
— |
— |
macOSPoC exploitHIGH2024-03-07
This issue was addressed with improved handling of symlinks. This issue is fixed in macOS Sonoma 14.4. An app may be able to create symlinks to protected regions of the disk.
CVEs:CVE-2024-23285
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| macos |
affected |
apple |
— |
— |
macOSPoC exploitHIGH2024-03-07
The issue was addressed with improved checks. This issue is fixed in macOS Monterey 12.7.4, macOS Sonoma 14.4, macOS Ventura 13.6.5. An app may be able to break out of its sandbox.
CVEs:CVE-2024-23299
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| macos |
affected |
apple |
— |
— |
macOSPoC exploitHIGH2024-03-07
The issue was addressed with improved memory handling. This issue is fixed in macOS Sonoma 14.4. Processing a file may lead to a denial-of-service or potentially disclose memory contents.
CVEs:CVE-2024-23249
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| macos |
affected |
apple |
— |
— |
visionOSPoC exploitCRITICAL2024-03-07
An out-of-bounds read was addressed with improved input validation. This issue is fixed in macOS Sonoma 14.4, visionOS 1.1. Processing an image may lead to arbitrary code execution.
CVEs:CVE-2024-23258
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| macos |
affected |
apple |
— |
— |
| visionos |
affected |
apple |
— |
— |
macOSPoC exploitMEDIUM2024-03-07
A logic issue was addressed with improved checks. This issue is fixed in macOS Monterey 12.7.4, macOS Sonoma 14.4, macOS Ventura 13.6.5. An attacker may gain access to protected parts of the file system.
CVEs:CVE-2024-23272
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| macos |
affected |
apple |
— |
— |
visionOSPoC exploitMEDIUM2024-03-07
The issue was addressed with improved handling of caches. This issue is fixed in iOS 17.4 and iPadOS 17.4, visionOS 1.1. An app may be able to fingerprint the user.
CVEs:CVE-2024-23220
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| ipad_os |
affected |
apple |
— |
— |
| iphone_os |
affected |
apple |
— |
— |
| visionos |
affected |
apple |
— |
— |
iPadOSPoC exploitMEDIUM2024-03-07
An access issue was addressed with improved access restrictions. This issue is fixed in iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4, tvOS 17.4, watchOS 10.4. An app may be able to access Bluetooth-connected microphones without user permission.
CVEs:CVE-2024-23250
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| ipad_os |
affected |
apple |
— |
— |
| iphone_os |
affected |
apple |
— |
— |
| macos |
affected |
apple |
— |
— |
| tvos |
affected |
apple |
— |
— |
| watchos |
affected |
apple |
— |
— |
macOSPoC exploitMEDIUM2024-03-07
This issue was addressed with improved state management. This issue is fixed in macOS Sonoma 14.4. An app may be able to access sensitive user data.
CVEs:CVE-2024-23281
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| macos |
affected |
apple |
— |
— |
macOSPoC exploitCRITICAL2024-03-07
A logic issue was addressed with improved restrictions. This issue is fixed in macOS Monterey 12.7.4, macOS Sonoma 14.4. An app from a standard user account may be able to escalate privilege after admin user login.
CVEs:CVE-2024-23244
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| macos |
affected |
apple |
— |
— |
macOSPoC exploitMEDIUM2024-03-07
The issue was addressed with improved checks. This issue is fixed in macOS Monterey 12.7.4, macOS Sonoma 14.4, macOS Ventura 13.6.5. An app may be able to modify protected parts of the file system.
CVEs:CVE-2024-23266
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| macos |
affected |
apple |
— |
— |
macOSPoC exploitMEDIUM2024-03-07
The issue was addressed with improved checks. This issue is fixed in macOS Monterey 12.7.4, macOS Sonoma 14.4, macOS Ventura 13.6.5. An app may be able to bypass certain Privacy preferences.
CVEs:CVE-2024-23267
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| macos |
affected |
apple |
— |
— |
iPadOSPoC exploitMEDIUM2024-03-07
A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4. An app may be able to access sensitive user data.
CVEs:CVE-2024-23205
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| ipad_os |
affected |
apple |
— |
— |
| iphone_os |
affected |
apple |
— |
— |
| macos |
affected |
apple |
— |
— |
macOSPoC exploitLOW2024-03-07
A privacy issue was addressed with improved handling of temporary files. This issue is fixed in macOS Sonoma 14.4. An app may be able to capture a user's screen.
CVEs:CVE-2024-23232
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| macos |
affected |
apple |
— |
— |
macOSPoC exploitHIGH2024-03-07
This issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14.4. Entitlements and privacy permissions granted to this app may be used by a malicious app.
CVEs:CVE-2024-23233
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| macos |
affected |
apple |
— |
— |
macOSPoC exploitHIGH2024-03-07
This issue was addressed by removing additional entitlements. This issue is fixed in macOS Sonoma 14.4. An app may be able to access user-sensitive data.
CVEs:CVE-2024-23260
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| macos |
affected |
apple |
— |
— |
iPadOSPoC exploitLOW2024-03-07
A privacy issue was addressed by not logging contents of text fields. This issue is fixed in iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4. An app may be able to view Mail data.
CVEs:CVE-2024-23242
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| ipad_os |
affected |
apple |
— |
— |
| iphone_os |
affected |
apple |
— |
— |
| macos |
affected |
apple |
— |
— |
macOSPoC exploitHIGH2024-03-07
An access issue was addressed with improved access restrictions. This issue is fixed in macOS Sonoma 14.4. An app may be able to edit NVRAM variables.
CVEs:CVE-2024-23238
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| macos |
affected |
apple |
— |
— |
macOSPoC exploitMEDIUM2024-03-07
This issue was addressed with improved file handling. This issue is fixed in macOS Monterey 12.7.4, macOS Sonoma 14.4, macOS Ventura 13.6.5. An app may be able to access sensitive user data.
CVEs:CVE-2024-23230
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| macos |
affected |
apple |
— |
— |
macOSPoC exploitMEDIUM2024-03-07
A race condition was addressed with additional validation. This issue is fixed in macOS Monterey 12.7.4, macOS Sonoma 14.4, macOS Ventura 13.6.5. An app may be able to access protected user data.
CVEs:CVE-2024-23275
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| macos |
affected |
apple |
— |
— |
OtherCoalition ESS < 30%HIGH2024-03-29
Swift Prometheus is a Swift client for the Prometheus monitoring system, supporting counters, gauges and histograms. In code which applies _un-sanitized string values into metric names or labels_, an attacker could make use of this and send a `?lang` q...
CVEs:CVE-2024-28867
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| swift_prometheus |
affected |
apple |
— |
— |
visionOSCoalition ESS < 30%MEDIUM2024-03-08
A permissions issue was addressed to help ensure Personas are always protected. This issue is fixed in visionOS 1.1. An unauthenticated user may be able to use an unprotected Persona.
CVEs:CVE-2024-23295
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| visionos |
affected |
apple |
— |
— |
OtherCoalition ESS < 30%HIGH2024-03-14
A logic issue was addressed with improved checks. This issue is fixed in iTunes 12.13.1 for Windows. A local attacker may be able to elevate their privileges.
CVEs:CVE-2023-42938
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| itunes |
affected |
apple |
— |
— |