CERT-In Advisory
CIAD-2024-0007
Multiple vulnerabilities in Apple Products
Original Issue Date: January 31, 2024
Severity Rating: High
Software Affected
- Apple tvOS versions prior to 17.3
- Apple TV HD and Apple TV 4K (all models)
- Apple watchOS versions prior to 10.3
- Apple Watch Series 4 and later
- Apple macOS Monterey versions prior to 12.7.3
- Apple macOS Ventura versions prior to 13.6.4
- Apple macOS Sonoma versions prior to 14.3
- Apple iOS and iPadOS versions prior to 15.8.1
- iPhone 6s (all models), iPhone 7 (all models), iPhone SE (1st generation), iPad Air 2, iPad mini (4th generation), and iPod touch (7th generation)
- Apple iOS and iPadOS versions prior to 16.7.5
- iPhone 8, iPhone 8 Plus, iPhone X, iPad 5th generation, iPad Pro 9.7-inch, and iPad Pro 12.9-inch 1st generation
- Apple iOS and iPadOS versions prior to 17.3
- iPhone XS and later, iPad Pro 12.9-inch 2nd generation and later, iPad Pro 10.5-inch, iPad Pro 11-inch 1st generation and later, iPad Air 3rd generation and later, iPad 6th generation and later, and iPad mini 5th generation and later
- Apple Safari versions prior to 17.3
- macOS Monterey and macOS Ventura
Overview
Multiple vulnerabilities have been reported in Apple products which could allow an attacker to access sensitive information, execute arbitrary code, bypass security restrictions and gain elevated privileges on the targeted system.
Description
Multiple vulnerabilities have been reported in Apple products:

Solution
Apply appropriate security updates as mentioned in the
Apple Security Update.
Vendor Information
Apple
https://support.apple.com/en-gb/HT214056
https://support.apple.com/en-gb/HT214059
https://support.apple.com/en-gb/HT214063
https://support.apple.com/en-gb/HT214062
https://support.apple.com/en-gb/HT214061
https://support.apple.com/en-gb/HT214058
https://support.apple.com/en-gb/HT214057
https://support.apple.com/en-gb/HT214060
https://support.apple.com/en-gb/HT214055
References
Apple
https://support.apple.com/en-gb/HT214056
https://support.apple.com/en-gb/HT214059
https://support.apple.com/en-gb/HT214063
https://support.apple.com/en-gb/HT214062
https://support.apple.com/en-gb/HT214061
https://support.apple.com/en-gb/HT214058
https://support.apple.com/en-gb/HT214057
https://support.apple.com/en-gb/HT214060
https://support.apple.com/en-gb/HT214055
CVE Name
CVE-2023-38039
CVE-2023-38545
CVE-2023-38546
CVE-2023-40528
CVE-2023-42887
CVE-2023-42888
CVE-2023-42915
CVE-2023-42935
CVE-2023-42937
CVE-2024-23203
CVE-2024-23204
CVE-2024-23206
CVE-2024-23207
CVE-2024-23208
CVE-2024-23209
CVE-2024-23210
CVE-2024-23211
CVE-2024-23212
CVE-2024-23213
CVE-2024-23214
CVE-2024-23215
CVE-2024-23217
CVE-2024-23218
CVE-2024-23219
CVE-2024-23222
CVE-2024-23223
CVE-2024-23224
Disclaimer
The information provided herein is on "as is" basis, without warranty of any kind.
Contact Information
Email: info@cert-in.org.in Phone: +91-11-22902657
Postal address
Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology Government of India Electronics Niketan 6, CGO Complex, Lodhi Road, New Delhi - 110 003 India
|