KEV · Actively exploited
CVE-2024-23222
CVE-2024-23222 is actively exploited (CISA KEV catalog) : high severity (CVSS 8.8), 0 tracked apps concerned, none still exposed on their current version.
- Severity (CVSS)
- 8.8
- Exploitation
- Confirmed
- Tracked apps
- 0
- Still exposed
- 0
NVD scale
CISA KEV · EPSS predicts 10.6 %
A type confusion issue was addressed with improved checks. This issue is fixed in Safari 17.3, iOS 15.8.7 and iPadOS 15.8.7, iOS 16.7.5 and iPadOS 16.7.5, iOS 17.3 and iPadOS 17.3, macOS Monterey 12.7.3, macOS Sonoma 14.3, macOS Ventura 13.6.4, tvOS 17.3, visionOS 1.0.2. Processing maliciously crafted web content may lead to arbitrary code execution. This fix associated with the Coruna exploit was shipped in iOS 17.3 on January 22, 2024. This update brings that fix to devices that cannot update to the latest iOS version.
Show raw CVSS vector
CISA Known Exploited Vulnerability
- Added to KEV
- 2024-01-23
- Remediation deadline
- 2024-02-13
- Required action
- Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
- Ransomware
- Unknown (not documented by CISA)
OS versions that fix this CVE
This CVE is resolved by the following OS security releases. Update the OS to at least the listed version.
Manage your fleet with Appaloosa
Appaloosa pushes OS updates, apps and policies to your Windows, macOS, iOS and Android devices from one console.