CyberzSOC

Publication detail
← Back to advisories & guidance

2024-025: Zero-Day Vulnerabilities in Apple Products ↗ source

March 7, 2024 CERT-EU Advisory

Summary

The two zero-day vulnerabilities, namely CVE-2024-23225 and CVE-2024-23296 , respectively exist in the iOS Kernel and RTKit. A memory corruption in those components would allow an attacker with arbitrary kernel read and write capability to bypass kernel memory protections. The list of impacted Apple devices includes: CERT-EU strongly recommends updating affected devices as soon as possible.

News Coverage

No coverage found in monitored research blogs or news feeds.

CVEs Referenced in This Publication

CVECVSSAffected
CVE-2024-23225 7.8 High Apple Multiple Products Apple iOS, iPadOS, macOS, tvOS, watchOS, and visionOS kernel contain a memory corruption vulnerability that allows an attacker with arbitrary kernel …
CVE-2024-23296 7.8 High Apple Multiple Products Apple iOS, iPadOS, macOS, tvOS, and watchOS RTKit contain a memory corruption vulnerability that allows an attacker with arbitrary kernel read and wr…

Extracted from the publication text. Each CVE links to its tracked detail page.

Vendors Named in This Publication

Each vendor links to its Known Exploited Vulnerabilities catalog page. Only vendors that appear in the KEV catalog are listed, either because the publication cites one of their KEV entries or because it names them directly.