CVE-2024-23296

CVSS 3.1 Score 7.8 of 10 (high)

Details

Published Mar 5, 2024
Updated: Aug 14, 2024
CWE ID 787

Summary

CVE-2024-23296 is a memory corruption vulnerability that has been addressed in iOS 17.4 and iPadOS 17.4. The issue allows an attacker with arbitrary kernel read and write capability to potentially bypass kernel memory protections. Apple has acknowledged that this vulnerability may have already been exploited. The vulnerability was resolved through improved validation to mitigate the risk to users.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share