Apple Releases Security Updates for Zero Day Vulnerability for Multiple Products
The security update addresses twenty-eight vulnerabilities for multiple products, including one zero day vulnerability
Summary
The security update addresses twenty-eight vulnerabilities for multiple products, including one zero day vulnerability
Affected platforms
The following platforms are known to be affected:
Threat details
Introduction
Apple has released a security update to address one zero day vulnerability and several further vulnerabilities for multiple products.
The zero day vulnerability, CVE-2024-23222, is a type confusion bug in the WebKit browser engine which could allow an attacker to perform arbitrary code execution when processing maliciously crafted web content.
Exploitation of CVE-2024-23222
Apple has reported that CVE-2024-23222 may be actively exploited.
Remediation advice
Affected organisations are encouraged to review the following Apple security advisory and apply any relevant updates or workarounds.
Remediation steps
| Type | Step |
|---|---|
| Patch |
Safari 17.3|HT214056 https://support.apple.com/kb/HT214056 |
| Patch |
iOS 17.3 and iPadOS 17.3|HT214059 https://support.apple.com/kb/HT214059 |
| Patch |
macOS Sonoma 14.3|HT214061 https://support.apple.com/kb/HT214061 |
| Patch |
macOS Ventura 13.6.4|HT214058 https://support.apple.com/kb/HT214058 |
| Patch |
macOS Monterey 12.7.3|HT214057 https://support.apple.com/kb/HT214057 |
| Patch |
watchOS 10.3|HT214060 https://support.apple.com/kb/HT214060 |
| Patch |
tvOS 17.3|HT214055 https://support.apple.com/kb/HT214055 |
Definitive source of threat updates
CVE Vulnerabilities
Last edited: 25 January 2024 4:00 pm