Apple Security Advisories · March 2024 — Apple Security Advisories
79 advisories 79 CVEs 2 EXPLOITED

Apple-vendor CVEs for 2024-03. Mirrored into Vulnetix VDB.

Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity). 2 are already weaponised in the wild — see the Exploited section.

What would you fix first?

The advisories below are ordered by the Vulnetix risk prioritization strategy: exploitation evidence first, scores second. On the interactive page you can switch to three other lenses.

Advisories

CVE-2024-23225

visionOSExploitedCISA KEV listedCRITICAL2024-03-05

A memory corruption issue was addressed with improved validation. This issue is fixed in iOS 16.7.6 and iPadOS 16.7.6, iOS 17.4 and iPadOS 17.4, macOS Monterey 12.7.4, macOS Sonoma 14.4, macOS Ventura 13.6.5, tvOS 17.4, visionOS 1.1, watchOS 10.4. An a...

CVEs:CVE-2024-23225

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
tvos affected apple
visionos affected apple
watchos affected apple
Upstream advisory

CVE-2024-23296

visionOSExploitedCISA KEV listedCRITICAL2024-03-05

A memory corruption issue was addressed with improved validation. This issue is fixed in iOS 16.7.8 and iPadOS 16.7.8, iOS 17.4 and iPadOS 17.4, macOS Monterey 12.7.6, macOS Sonoma 14.4, macOS Ventura 13.6.7, tvOS 17.4, visionOS 1.1, watchOS 10.4. An a...

CVEs:CVE-2024-23296

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
tvos affected apple
visionos affected apple
watchos affected apple
Upstream advisory

CVE-2024-23243

iPadOSActive exploitation (sightings)MEDIUM2024-03-05

A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in iOS 17.4 and iPadOS 17.4. An app may be able to read sensitive location information.

CVEs:CVE-2024-23243

Affected products

ProductStatusVendorPackageEcosystem
ipad_os affected apple
iphone_os affected apple
Upstream advisory

CVE-2024-23298

XcodeActive exploitation (sightings)MEDIUM2024-03-15

A logic issue was addressed with improved state management. This issue is fixed in Xcode 15.3. An app may bypass Gatekeeper checks.

CVEs:CVE-2024-23298

Affected products

ProductStatusVendorPackageEcosystem
xcode affected apple
Upstream advisory

CVE-2024-23262

visionOSActive exploitation (sightings)MEDIUM2024-03-07

This issue was addressed with additional entitlement checks. This issue is fixed in iOS 16.7.6 and iPadOS 16.7.6, iOS 17.4 and iPadOS 17.4, visionOS 1.1. An app may be able to spoof system notifications and UI.

CVEs:CVE-2024-23262

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
visionos affected apple
Upstream advisory

CVE-2024-23300

OtherActive exploitation (sightings)CRITICAL2024-03-12

A use-after-free issue was addressed with improved memory management. This issue is fixed in GarageBand 10.4.11. Processing a maliciously crafted file may lead to unexpected app termination or arbitrary code execution.

CVEs:CVE-2024-23300

Affected products

ProductStatusVendorPackageEcosystem
garageband affected apple
Upstream advisory

CVE-2024-23256

iPadOSActive exploitation (sightings)LOW2024-03-05

A logic issue was addressed with improved state management. This issue is fixed in iOS 17.4 and iPadOS 17.4. A user's locked tabs may be briefly visible while switching tab groups when Locked Private Browsing is enabled.

CVEs:CVE-2024-23256

Affected products

ProductStatusVendorPackageEcosystem
ipad_os affected apple
iphone_os affected apple
Upstream advisory

CVE-2024-23240

iPadOSActive exploitation (sightings)LOW2024-03-07

The issue was addressed with improved checks. This issue is fixed in iOS 17.4 and iPadOS 17.4. Shake-to-undo may allow a deleted photo to be re-surfaced without authentication.

CVEs:CVE-2024-23240

Affected products

ProductStatusVendorPackageEcosystem
ipad_os affected apple
iphone_os affected apple
Upstream advisory

CVE-2024-2398

OtherPoC exploitHIGH2024-03-26

When an application tells libcurl it wants to allow HTTP/2 server push, and the amount of received headers for the push surpasses the maximum allowed limit (1000), libcurl aborts the server push. When aborting, libcurl inadvertently does not free all t...

CVEs:CVE-2024-2398

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2024-2379

OtherPoC exploitMEDIUM2024-03-26

libcurl skips the certificate verification for a QUIC connection under certain conditions, when built to use wolfSSL. If told to use an unknown/bad cipher or curve, the error path accidentally skips the verification and returns OK, thus ignoring any ce...

CVEs:CVE-2024-2379

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2024-2004

OtherPoC exploitLOW2024-03-26

When a protocol selection parameter option disables all protocols without adding any then the default set of protocols would remain in the allowed set due to an error in the logic for removing protocols. The below command would perform a request to cur...

CVEs:CVE-2024-2004

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2024-23263

visionOSPoC exploitCRITICAL2024-03-07

A logic issue was addressed with improved validation. This issue is fixed in Safari 17.4, iOS 16.7.6 and iPadOS 16.7.6, iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4, tvOS 17.4, visionOS 1.1, watchOS 10.4. Processing maliciously crafted web content may p...

CVEs:CVE-2024-23263

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
safari affected apple
tvos affected apple
visionos affected apple
watchos affected apple
Upstream advisory

CVE-2024-23284

visionOSPoC exploitCRITICAL2024-03-07

A logic issue was addressed with improved state management. This issue is fixed in Safari 17.4, iOS 16.7.6 and iPadOS 16.7.6, iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4, tvOS 17.4, visionOS 1.1, watchOS 10.4. Processing maliciously crafted web content...

CVEs:CVE-2024-23284

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
safari affected apple
tvos affected apple
visionos affected apple
watchos affected apple
Upstream advisory

CVE-2024-2466

OtherPoC exploitMEDIUM2024-03-26

libcurl did not check the server certificate of TLS connections done to a host specified as an IP address, when built to use mbedTLS. libcurl would wrongly avoid using the set hostname function when the specified hostname was given as an IP address, t...

CVEs:CVE-2024-2466

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2024-23280

iPadOSPoC exploitHIGH2024-03-07

An injection issue was addressed with improved validation. This issue is fixed in Safari 17.4, iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4, tvOS 17.4, watchOS 10.4. A maliciously crafted webpage may be able to fingerprint the user.

CVEs:CVE-2024-23280

Affected products

ProductStatusVendorPackageEcosystem
ipad_os affected apple
iphone_os affected apple
macos affected apple
safari affected apple
tvos affected apple
watchos affected apple
Upstream advisory

CVE-2024-23254

visionOSPoC exploitMEDIUM2024-03-07

The issue was addressed with improved UI handling. This issue is fixed in Safari 17.4, iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4, tvOS 17.4, visionOS 1.1, watchOS 10.4. A malicious website may exfiltrate audio data cross-origin.

CVEs:CVE-2024-23254

Affected products

ProductStatusVendorPackageEcosystem
ipad_os affected apple
iphone_os affected apple
macos affected apple
safari affected apple
tvos affected apple
visionos affected apple
watchos affected apple
Upstream advisory

CVE-2024-23286

visionOSPoC exploitCRITICAL2024-03-07

A buffer overflow issue was addressed with improved memory handling. This issue is fixed in iOS 16.7.6 and iPadOS 16.7.6, iOS 17.4 and iPadOS 17.4, macOS Monterey 12.7.4, macOS Sonoma 14.4, macOS Ventura 13.6.5, tvOS 17.4, visionOS 1.1, watchOS 10.4. P...

CVEs:CVE-2024-23286

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
tvos affected apple
visionos affected apple
watchos affected apple
Upstream advisory

CVE-2024-23259

iPadOSPoC exploitHIGH2024-03-07

The issue was addressed with improved checks. This issue is fixed in iOS 16.7.6 and iPadOS 16.7.6, iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4. Processing web content may lead to a denial-of-service.

CVEs:CVE-2024-23259

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
Upstream advisory

CVE-2024-23264

visionOSPoC exploitMEDIUM2024-03-07

A validation issue was addressed with improved input sanitization. This issue is fixed in iOS 16.7.6 and iPadOS 16.7.6, iOS 17.4 and iPadOS 17.4, macOS Monterey 12.7.4, macOS Sonoma 14.4, macOS Ventura 13.6.5, tvOS 17.4, visionOS 1.1. An application ma...

CVEs:CVE-2024-23264

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
tvos affected apple
visionos affected apple
Upstream advisory

CVE-2024-23273

iPadOSPoC exploitMEDIUM2024-03-07

This issue was addressed through improved state management. This issue is fixed in Safari 17.4, iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4. Private Browsing tabs may be accessed without authentication.

CVEs:CVE-2024-23273

Affected products

ProductStatusVendorPackageEcosystem
ipad_os affected apple
iphone_os affected apple
macos affected apple
safari affected apple
Upstream advisory

CVE-2024-23265

visionOSPoC exploitCRITICAL2024-03-07

A memory corruption vulnerability was addressed with improved locking. This issue is fixed in iOS 16.7.6 and iPadOS 16.7.6, iOS 17.4 and iPadOS 17.4, macOS Monterey 12.7.4, macOS Sonoma 14.4, macOS Ventura 13.6.5, tvOS 17.4, visionOS 1.1, watchOS 10.4....

CVEs:CVE-2024-23265

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
tvos affected apple
visionos affected apple
watchos affected apple
Upstream advisory

CVE-2024-23277

iPadOSPoC exploitMEDIUM2024-03-07

The issue was addressed with improved checks. This issue is fixed in iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4. An attacker in a privileged network position may be able to inject keystrokes by spoofing a keyboard.

CVEs:CVE-2024-23277

Affected products

ProductStatusVendorPackageEcosystem
ipad_os affected apple
iphone_os affected apple
macos affected apple
Upstream advisory

CVE-2024-23246

visionOSPoC exploitHIGH2024-03-07

This issue was addressed by removing the vulnerable code. This issue is fixed in iOS 16.7.6 and iPadOS 16.7.6, iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4, tvOS 17.4, visionOS 1.1, watchOS 10.4. An app may be able to break out of its sandbox.

CVEs:CVE-2024-23246

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
tvos affected apple
visionos affected apple
watchos affected apple
Upstream advisory

CVE-2024-23287

iPadOSPoC exploitHIGH2024-03-07

A privacy issue was addressed with improved handling of temporary files. This issue is fixed in iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4, watchOS 10.4. An app may be able to access user-sensitive data.

CVEs:CVE-2024-23287

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
watchos affected apple
Upstream advisory

CVE-2024-23255

iPadOSPoC exploitCRITICAL2024-03-07

An authentication issue was addressed with improved state management. This issue is fixed in iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4. Photos in the Hidden Photos Album may be viewed without authentication.

CVEs:CVE-2024-23255

Affected products

ProductStatusVendorPackageEcosystem
ipad_os affected apple
iphone_os affected apple
macos affected apple
Upstream advisory

CVE-2024-23291

iPadOSPoC exploitHIGH2024-03-07

A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4, tvOS 17.4, watchOS 10.4. A malicious app may be able to observe user data in log entries related to ...

CVEs:CVE-2024-23291

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
tvos affected apple
watchos affected apple
Upstream advisory

CVE-2024-27859

visionOSPoC exploitCRITICAL2024-03-07

The issue was addressed with improved memory handling. This issue is fixed in iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4, tvOS 17.4, visionOS 1.1, watchOS 10.4. Processing web content may lead to arbitrary code execution.

CVEs:CVE-2024-27859

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
tvos affected apple
visionos affected apple
watchos affected apple
Upstream advisory

CVE-2024-23235

visionOSPoC exploitHIGH2024-03-07

A race condition was addressed with additional validation. This issue is fixed in iOS 16.7.6 and iPadOS 16.7.6, iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4, tvOS 17.4, visionOS 1.1, watchOS 10.4. An app may be able to access user-sensitive data.

CVEs:CVE-2024-23235

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
tvos affected apple
visionos affected apple
watchos affected apple
Upstream advisory

CVE-2024-23290

iPadOSPoC exploitHIGH2024-03-07

A logic issue was addressed with improved restrictions. This issue is fixed in iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4, tvOS 17.4, watchOS 10.4. An app may be able to access user-sensitive data.

CVEs:CVE-2024-23290

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
tvos affected apple
watchos affected apple
Upstream advisory

CVE-2024-23278

iPadOSPoC exploitHIGH2024-03-07

The issue was addressed with improved checks. This issue is fixed in iOS 16.7.6 and iPadOS 16.7.6, iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4, macOS Ventura 13.6.5, tvOS 17.4, watchOS 10.4. An app may be able to break out of its sandbox.

CVEs:CVE-2024-23278

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
tvos affected apple
watchos affected apple
Upstream advisory

CVE-2024-23248

macOSPoC exploitHIGH2024-03-07

The issue was addressed with improved memory handling. This issue is fixed in macOS Sonoma 14.4. Processing a file may lead to a denial-of-service or potentially disclose memory contents.

CVEs:CVE-2024-23248

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2024-23257

visionOSPoC exploitLOW2024-03-07

The issue was addressed with improved memory handling. This issue is fixed in iOS 16.7.6 and iPadOS 16.7.6, macOS Monterey 12.7.4, macOS Sonoma 14.4, macOS Ventura 13.6.5, visionOS 1.1. Processing an image may result in disclosure of process memory.

CVEs:CVE-2024-23257

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
visionos affected apple
Upstream advisory

CVE-2024-23241

iPadOSPoC exploitMEDIUM2024-03-07

This issue was addressed through improved state management. This issue is fixed in iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4, tvOS 17.4. An app may be able to leak sensitive user information.

CVEs:CVE-2024-23241

Affected products

ProductStatusVendorPackageEcosystem
ipad_os affected apple
iphone_os affected apple
macos affected apple
tvos affected apple
Upstream advisory

CVE-2024-23245

macOSPoC exploitCRITICAL2024-03-07

This issue was addressed by adding an additional prompt for user consent. This issue is fixed in macOS Monterey 12.7.4, macOS Sonoma 14.4, macOS Ventura 13.6.5. Third-party shortcuts may use a legacy action from Automator to send events to apps without...

CVEs:CVE-2024-23245

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2024-23239

iPadOSPoC exploitMEDIUM2024-03-07

A race condition was addressed with improved state handling. This issue is fixed in iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4, tvOS 17.4, watchOS 10.4. An app may be able to leak sensitive user information.

CVEs:CVE-2024-23239

Affected products

ProductStatusVendorPackageEcosystem
ipad_os affected apple
iphone_os affected apple
macos affected apple
tvos affected apple
watchos affected apple
Upstream advisory

CVE-2024-23268

macOSPoC exploitHIGH2024-03-07

An injection issue was addressed with improved input validation. This issue is fixed in macOS Monterey 12.7.4, macOS Sonoma 14.4, macOS Ventura 13.6.5. An app may be able to elevate privileges.

CVEs:CVE-2024-23268

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2024-23274

macOSPoC exploitHIGH2024-03-07

An injection issue was addressed with improved input validation. This issue is fixed in macOS Monterey 12.7.4, macOS Sonoma 14.4, macOS Ventura 13.6.5. An app may be able to elevate privileges.

CVEs:CVE-2024-23274

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2024-23293

iPadOSPoC exploitMEDIUM2024-03-07

This issue was addressed through improved state management. This issue is fixed in iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4, tvOS 17.4, watchOS 10.4. An attacker with physical access may be able to use Siri to access sensitive user data.

CVEs:CVE-2024-23293

Affected products

ProductStatusVendorPackageEcosystem
ipad_os affected apple
iphone_os affected apple
macos affected apple
tvos affected apple
watchos affected apple
Upstream advisory

CVE-2024-23253

macOSPoC exploitHIGH2024-03-07

A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sonoma 14.4. An app may be able to access a user's Photos Library.

CVEs:CVE-2024-23253

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2024-23247

macOSPoC exploitCRITICAL2024-03-07

The issue was addressed with improved memory handling. This issue is fixed in macOS Monterey 12.7.4, macOS Sonoma 14.4, macOS Ventura 13.6.5. Processing a file may lead to unexpected app termination or arbitrary code execution.

CVEs:CVE-2024-23247

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2024-23289

iPadOSPoC exploitMEDIUM2024-03-07

A lock screen issue was addressed with improved state management. This issue is fixed in iOS 16.7.6 and iPadOS 16.7.6, iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4, watchOS 10.4. A person with physical access to a device may be able to use Siri to acces...

CVEs:CVE-2024-23289

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
watchos affected apple
Upstream advisory

CVE-2024-23276

macOSPoC exploitHIGH2024-03-07

A logic issue was addressed with improved checks. This issue is fixed in macOS Monterey 12.7.4, macOS Sonoma 14.4, macOS Ventura 13.6.5. An app may be able to elevate privileges.

CVEs:CVE-2024-23276

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2024-23297

iPadOSPoC exploitMEDIUM2024-03-07

The issue was addressed with improved checks. This issue is fixed in iOS 17.4 and iPadOS 17.4, tvOS 17.4, watchOS 10.4. A malicious application may be able to access private information.

CVEs:CVE-2024-23297

Affected products

ProductStatusVendorPackageEcosystem
ipad_os affected apple
iphone_os affected apple
tvos affected apple
watchos affected apple
Upstream advisory

CVE-2024-23294

macOSPoC exploitCRITICAL2024-03-07

This issue was addressed by removing the vulnerable code. This issue is fixed in macOS Sonoma 14.4. Processing malicious input may lead to code execution.

CVEs:CVE-2024-23294

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2024-23270

iPadOSPoC exploitCRITICAL2024-03-07

The issue was addressed with improved memory handling. This issue is fixed in iOS 17.4 and iPadOS 17.4, macOS Monterey 12.7.4, macOS Sonoma 14.4, macOS Ventura 13.6.5, tvOS 17.4. An app may be able to execute arbitrary code with kernel privileges.

CVEs:CVE-2024-23270

Affected products

ProductStatusVendorPackageEcosystem
ipad_os affected apple
iphone_os affected apple
macos affected apple
tvos affected apple
Upstream advisory

CVE-2024-23216

macOSPoC exploitHIGH2024-03-07

A path handling issue was addressed with improved validation. This issue is fixed in macOS Monterey 12.7.4, macOS Sonoma 14.4, macOS Ventura 13.6.5. An app may be able to overwrite arbitrary files.

CVEs:CVE-2024-23216

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2024-23231

iPadOSPoC exploitHIGH2024-03-07

A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in iOS 16.7.6 and iPadOS 16.7.6, iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4, macOS Ventura 13.6.5, watchOS 10.4. An app may be able to access user-...

CVEs:CVE-2024-23231

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
watchos affected apple
Upstream advisory

CVE-2024-23288

iPadOSPoC exploitHIGH2024-03-07

This issue was addressed by removing the vulnerable code. This issue is fixed in iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4, tvOS 17.4, watchOS 10.4. An app may be able to elevate privileges.

CVEs:CVE-2024-23288

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
tvos affected apple
watchos affected apple
Upstream advisory

CVE-2024-0258

iPadOSPoC exploitCRITICAL2024-03-07

The issue was addressed with improved memory handling. This issue is fixed in iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4, tvOS 17.4, watchOS 10.4. An app may be able to execute arbitrary code out of its sandbox or with certain elevated privileges.

CVEs:CVE-2024-0258

Affected products

ProductStatusVendorPackageEcosystem
ipad_os affected apple
iphone_os affected apple
macos affected apple
tvos affected apple
watchos affected apple
Upstream advisory

CVE-2024-23283

iPadOSPoC exploitHIGH2024-03-07

A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in iOS 16.7.6 and iPadOS 16.7.6, macOS Monterey 12.7.4, macOS Sonoma 14.4, macOS Ventura 13.6.5. An app may be able to access user-sensitive data.

CVEs:CVE-2024-23283

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
Upstream advisory

CVE-2024-23234

macOSPoC exploitCRITICAL2024-03-07

An out-of-bounds write issue was addressed with improved input validation. This issue is fixed in macOS Monterey 12.7.4, macOS Sonoma 14.4, macOS Ventura 13.6.5. An app may be able to execute arbitrary code with kernel privileges.

CVEs:CVE-2024-23234

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2024-23292

iPadOSPoC exploitLOW2024-03-07

This issue was addressed with improved data protection. This issue is fixed in iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4. An app may be able to access information about a user's contacts.

CVEs:CVE-2024-23292

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
Upstream advisory

CVE-2023-28826

iPadOSPoC exploitHIGH2024-03-07

This issue was addressed with improved redaction of sensitive information. This issue is fixed in iOS 16.7.6 and iPadOS 16.7.6, macOS Monterey 12.7.4, macOS Sonoma 14.1, macOS Ventura 13.6.5. An app may be able to access sensitive user data.

CVEs:CVE-2023-28826

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
Upstream advisory

CVE-2024-23279

macOSPoC exploitHIGH2024-03-07

A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in macOS Sonoma 14.4. An app may be able to access user-sensitive data.

CVEs:CVE-2024-23279

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2024-23201

iPadOSPoC exploitHIGH2024-03-07

A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 17.3 and iPadOS 17.3, macOS Monterey 12.7.4, macOS Sonoma 14.3, macOS Ventura 13.6.5, tvOS 17.3, watchOS 10.3. An app may be able to cause a denial-of-service.

CVEs:CVE-2024-23201

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
tvos affected apple
watchos affected apple
Upstream advisory

CVE-2024-23227

macOSPoC exploitHIGH2024-03-07

This issue was addressed with improved redaction of sensitive information. This issue is fixed in macOS Monterey 12.7.4, macOS Sonoma 14.4, macOS Ventura 13.6.5. An app may be able to read sensitive location information.

CVEs:CVE-2024-23227

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2024-23269

macOSPoC exploitMEDIUM2024-03-07

A downgrade issue affecting Intel-based Mac computers was addressed with additional code-signing restrictions. This issue is fixed in macOS Monterey 12.7.4, macOS Sonoma 14.4, macOS Ventura 13.6.5. An app may be able to modify protected parts of the fi...

CVEs:CVE-2024-23269

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2024-23285

macOSPoC exploitHIGH2024-03-07

This issue was addressed with improved handling of symlinks. This issue is fixed in macOS Sonoma 14.4. An app may be able to create symlinks to protected regions of the disk.

CVEs:CVE-2024-23285

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2024-23299

macOSPoC exploitHIGH2024-03-07

The issue was addressed with improved checks. This issue is fixed in macOS Monterey 12.7.4, macOS Sonoma 14.4, macOS Ventura 13.6.5. An app may be able to break out of its sandbox.

CVEs:CVE-2024-23299

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2024-23249

macOSPoC exploitHIGH2024-03-07

The issue was addressed with improved memory handling. This issue is fixed in macOS Sonoma 14.4. Processing a file may lead to a denial-of-service or potentially disclose memory contents.

CVEs:CVE-2024-23249

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2024-23258

visionOSPoC exploitCRITICAL2024-03-07

An out-of-bounds read was addressed with improved input validation. This issue is fixed in macOS Sonoma 14.4, visionOS 1.1. Processing an image may lead to arbitrary code execution.

CVEs:CVE-2024-23258

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
visionos affected apple
Upstream advisory

CVE-2024-23272

macOSPoC exploitMEDIUM2024-03-07

A logic issue was addressed with improved checks. This issue is fixed in macOS Monterey 12.7.4, macOS Sonoma 14.4, macOS Ventura 13.6.5. An attacker may gain access to protected parts of the file system.

CVEs:CVE-2024-23272

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2024-23220

visionOSPoC exploitMEDIUM2024-03-07

The issue was addressed with improved handling of caches. This issue is fixed in iOS 17.4 and iPadOS 17.4, visionOS 1.1. An app may be able to fingerprint the user.

CVEs:CVE-2024-23220

Affected products

ProductStatusVendorPackageEcosystem
ipad_os affected apple
iphone_os affected apple
visionos affected apple
Upstream advisory

CVE-2024-23250

iPadOSPoC exploitMEDIUM2024-03-07

An access issue was addressed with improved access restrictions. This issue is fixed in iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4, tvOS 17.4, watchOS 10.4. An app may be able to access Bluetooth-connected microphones without user permission.

CVEs:CVE-2024-23250

Affected products

ProductStatusVendorPackageEcosystem
ipad_os affected apple
iphone_os affected apple
macos affected apple
tvos affected apple
watchos affected apple
Upstream advisory

CVE-2024-23281

macOSPoC exploitMEDIUM2024-03-07

This issue was addressed with improved state management. This issue is fixed in macOS Sonoma 14.4. An app may be able to access sensitive user data.

CVEs:CVE-2024-23281

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2024-23244

macOSPoC exploitCRITICAL2024-03-07

A logic issue was addressed with improved restrictions. This issue is fixed in macOS Monterey 12.7.4, macOS Sonoma 14.4. An app from a standard user account may be able to escalate privilege after admin user login.

CVEs:CVE-2024-23244

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2024-23266

macOSPoC exploitMEDIUM2024-03-07

The issue was addressed with improved checks. This issue is fixed in macOS Monterey 12.7.4, macOS Sonoma 14.4, macOS Ventura 13.6.5. An app may be able to modify protected parts of the file system.

CVEs:CVE-2024-23266

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2024-23267

macOSPoC exploitMEDIUM2024-03-07

The issue was addressed with improved checks. This issue is fixed in macOS Monterey 12.7.4, macOS Sonoma 14.4, macOS Ventura 13.6.5. An app may be able to bypass certain Privacy preferences.

CVEs:CVE-2024-23267

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2024-23205

iPadOSPoC exploitMEDIUM2024-03-07

A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4. An app may be able to access sensitive user data.

CVEs:CVE-2024-23205

Affected products

ProductStatusVendorPackageEcosystem
ipad_os affected apple
iphone_os affected apple
macos affected apple
Upstream advisory

CVE-2024-23232

macOSPoC exploitLOW2024-03-07

A privacy issue was addressed with improved handling of temporary files. This issue is fixed in macOS Sonoma 14.4. An app may be able to capture a user's screen.

CVEs:CVE-2024-23232

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2024-23233

macOSPoC exploitHIGH2024-03-07

This issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14.4. Entitlements and privacy permissions granted to this app may be used by a malicious app.

CVEs:CVE-2024-23233

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2024-23260

macOSPoC exploitHIGH2024-03-07

This issue was addressed by removing additional entitlements. This issue is fixed in macOS Sonoma 14.4. An app may be able to access user-sensitive data.

CVEs:CVE-2024-23260

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2024-23242

iPadOSPoC exploitLOW2024-03-07

A privacy issue was addressed by not logging contents of text fields. This issue is fixed in iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4. An app may be able to view Mail data.

CVEs:CVE-2024-23242

Affected products

ProductStatusVendorPackageEcosystem
ipad_os affected apple
iphone_os affected apple
macos affected apple
Upstream advisory

CVE-2024-23238

macOSPoC exploitHIGH2024-03-07

An access issue was addressed with improved access restrictions. This issue is fixed in macOS Sonoma 14.4. An app may be able to edit NVRAM variables.

CVEs:CVE-2024-23238

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2024-23230

macOSPoC exploitMEDIUM2024-03-07

This issue was addressed with improved file handling. This issue is fixed in macOS Monterey 12.7.4, macOS Sonoma 14.4, macOS Ventura 13.6.5. An app may be able to access sensitive user data.

CVEs:CVE-2024-23230

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2024-23275

macOSPoC exploitMEDIUM2024-03-07

A race condition was addressed with additional validation. This issue is fixed in macOS Monterey 12.7.4, macOS Sonoma 14.4, macOS Ventura 13.6.5. An app may be able to access protected user data.

CVEs:CVE-2024-23275

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2024-28867

OtherCoalition ESS < 30%HIGH2024-03-29

Swift Prometheus is a Swift client for the Prometheus monitoring system, supporting counters, gauges and histograms. In code which applies _un-sanitized string values into metric names or labels_, an attacker could make use of this and send a `?lang` q...

CVEs:CVE-2024-28867

Affected products

ProductStatusVendorPackageEcosystem
swift_prometheus affected apple
Upstream advisory

CVE-2024-23295

visionOSCoalition ESS < 30%MEDIUM2024-03-08

A permissions issue was addressed to help ensure Personas are always protected. This issue is fixed in visionOS 1.1. An unauthenticated user may be able to use an unprotected Persona.

CVEs:CVE-2024-23295

Affected products

ProductStatusVendorPackageEcosystem
visionos affected apple
Upstream advisory

CVE-2023-42938

OtherCoalition ESS < 30%HIGH2024-03-14

A logic issue was addressed with improved checks. This issue is fixed in iTunes 12.13.1 for Windows. A local attacker may be able to elevate their privileges.

CVEs:CVE-2023-42938

Affected products

ProductStatusVendorPackageEcosystem
itunes affected apple
Upstream advisory

Need live exploit intelligence?

Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.