CERT-In Vulnerability Note
CIVN-2024-0090
Multiple vulnerabilities in Apple iOS and iPadOS
Original Issue Date:March 15, 2024
Severity Rating: HIGH
Software Affected
- Apple iOS and iPadOS versions prior to 16.7.6
(Available for iPhone 8, iPhone 8 Plus, iPhone X, iPad 5th generation, iPad Pro 9.7-inch, and iPad Pro 12.9-inch 1st generation) - Apple iOS and iPadOS versions prior to 17.4
(Available for iPhone XS and later, iPad Pro 12.9-inch 2nd generation and later, iPad Pro 10.5-inch, iPad Pro 11-inch 1st generation and later, iPad Air 3rd generation and later, iPad 6th generation and later, and iPad mini 5th generation and later)
Overview
Multiple vulnerabilities have been reported in Apple iOS and iPadOS which could allow an attacker to trigger denial of service condition, execute arbitrary code, sensitive information disclosure and bypass security restriction on the targeted system.
Description
These vulnerabilities exist in Apple iOS and iPadOS due to improper validation in Bluetooth, libxpc, MediaRemote, Photos, Safari & WebKit component; privacy issue in ExtensionKit, Messages, Share Sheet, Synapse & Notes component; buffer overflow issue in ImageIO component; memory corruption issue in kernel & RTKit component; logic issue in Safari Private Browsing & Sandbox; lock screen issue in Siri and timing side-channel issue in CoreCrypto component.
Successful exploitation of these vulnerabilities could allow the attacker to trigger denial of service condition, execute arbitrary code, sensitive information disclosure and bypass security restriction on the targeted system.
Solution
Apply appropriate updates as mentioned:
https://support.apple.com/en-us/HT214082
https://support.apple.com/en-us/HT214081
Vendor Information
Apple
https://support.apple.com/en-us/HT214082
https://support.apple.com/en-us/HT214081
References
Apple
https://support.apple.com/en-us/HT214082
https://support.apple.com/en-us/HT214081
CVE Name
CVE-2022-48554
CVE-2023-28826
CVE-2024-23262
CVE-2024-23218
CVE-2024-23286
CVE-2024-23257
CVE-2024-23225
CVE-2024-23235
CVE-2024-23265
CVE-2024-23278
CVE-2024-23264
CVE-2024-23283
CVE-2024-23259
CVE-2024-23231
CVE-2024-23204
CVE-2024-23203
CVE-2024-23289
CVE-2024-23246
CVE-2024-23284
CVE-2024-23263
CVE-2024-23243
CVE-2024-23291
CVE-2024-23288
CVE-2024-23277
CVE-2024-23250
CVE-2024-23205
CVE-2024-23270
CVE-2024-0258
CVE-2024-23297
CVE-2024-23287
CVE-2024-23240
CVE-2024-23255
CVE-2024-23296
CVE-2024-23220
CVE-2024-23256
CVE-2024-23273
CVE-2024-23239
CVE-2024-23290
CVE-2024-23292
CVE-2024-23293
CVE-2024-23241
CVE-2024-23242
CVE-2024-23226
CVE-2024-23252
CVE-2024-23254
CVE-2024-23280
Disclaimer
The information provided herein is on "as is" basis, without warranty of any kind.
Contact Information
Email: info@cert-in.org.in Phone: +91-11-22902657
Postal address
Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology Government of India Electronics Niketan 6, CGO Complex, Lodhi Road, New Delhi - 110 003 India
|