First published: Mon Jan 22 2024(Updated: )
Apple Neural Engine. The issue was addressed with improved memory handling.
Credit: fmyy @binary_fmyy TIANGONG Team of Legendsec at QIlime TIANGONG Team of Legendsec at QIKoh M. Nakagawa FFRI Security Incan anonymous researcher Noah Roskin-Frazee Pr Ian de Marcellus Mark Bowers Jubaer Alnazi @h33tjubaer Kirin @Pwnrin Zhongquan Li @Guluisacat Wangtaiyu Zhongfu infoJames Lee @Windowsrcer Clemens Lang Ye Zhang Baidu Security product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
Apple macOS | <14.3 | 14.3 |
tvOS | <17.3 | 17.3 |
Apple iOS, iPadOS, and watchOS | <10.3 | 10.3 |
Apple iOS and iPadOS | <17.3 | 17.3 |
Apple iOS, iPadOS, and macOS | <17.3 | 17.3 |
Apple iOS, iPadOS, and macOS | <17.3 | |
iPhone OS | <17.3 | |
macOS | >=14.0<14.3 | |
tvOS | <10.3 | |
Apple iOS, iPadOS, and watchOS | <10.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Appears in the following advisories)
(Found alongside the following vulnerabilities)
CVE-2024-23208 is classified as a high-severity vulnerability due to its potential to allow arbitrary code execution with kernel privileges.
To remediate CVE-2024-23208, users should update to macOS Sonoma 14.3, iOS 17.3, iPadOS 17.3, watchOS 10.3, or tvOS 17.3.
The exploitation of CVE-2024-23208 may lead to unauthorized access or control over affected devices, putting user data at risk.
CVE-2024-23208 affects devices running macOS, iOS, iPadOS, watchOS, and tvOS versions prior to the latest updates.
There is currently no public indication of active exploitation of CVE-2024-23208, but it is recommended to apply updates promptly.