Lucene search

K
vulnrichmentAppleVULNRICHMENT:CVE-2024-23278
HistoryMar 08, 2024 - 1:36 a.m.

CVE-2024-23278

2024-03-0801:36:11
apple
github.com
2
cve-2024-23278
macos ventura
macos sonoma
ios 17.4
ipados 17.4
watchos 10.4
ios 16.7.6
ipados 16.7.6
tvos 17.4
sandbox breakout

AI Score

5.2

Confidence

Low

SSVC

Exploitation

none

Automatable

no

Technical Impact

total

The issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.6.5, macOS Sonoma 14.4, iOS 17.4 and iPadOS 17.4, watchOS 10.4, iOS 16.7.6 and iPadOS 16.7.6, tvOS 17.4. An app may be able to break out of its sandbox.

ADP Affected

[
  {
    "cpes": [
      "cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:*"
    ],
    "vendor": "apple",
    "product": "macos",
    "versions": [
      {
        "status": "affected",
        "version": "13.0",
        "lessThan": "13.6",
        "versionType": "custom"
      },
      {
        "status": "affected",
        "version": "14.0",
        "lessThan": "14.4",
        "versionType": "custom"
      }
    ],
    "defaultStatus": "unknown"
  },
  {
    "cpes": [
      "cpe:2.3:o:apple:tvos:*:*:*:*:*:*:*:*"
    ],
    "vendor": "apple",
    "product": "tvos",
    "versions": [
      {
        "status": "affected",
        "version": "0",
        "lessThan": "17.4",
        "versionType": "custom"
      }
    ],
    "defaultStatus": "unknown"
  },
  {
    "cpes": [
      "cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*",
      "cpe:2.3:o:apple:iphone_os:17.0:*:*:*:*:*:*:*"
    ],
    "vendor": "apple",
    "product": "iphone_os",
    "versions": [
      {
        "status": "affected",
        "version": "0",
        "lessThan": "16.7.6",
        "versionType": "custom"
      },
      {
        "status": "affected",
        "version": "17.0",
        "lessThan": "17.4",
        "versionType": "custom"
      }
    ],
    "defaultStatus": "unknown"
  },
  {
    "cpes": [
      "cpe:2.3:o:apple:ipad_os:*:*:*:*:*:*:*:*",
      "cpe:2.3:o:apple:ipad_os:17.0:*:*:*:*:*:*:*"
    ],
    "vendor": "apple",
    "product": "ipad_os",
    "versions": [
      {
        "status": "affected",
        "version": "0",
        "lessThan": "16.7.6",
        "versionType": "custom"
      },
      {
        "status": "affected",
        "version": "17.0",
        "lessThan": "17.4",
        "versionType": "custom"
      }
    ],
    "defaultStatus": "unknown"
  }
]

AI Score

5.2

Confidence

Low

SSVC

Exploitation

none

Automatable

no

Technical Impact

total

Related for VULNRICHMENT:CVE-2024-23278