Vulnerability record · CVE-2024-23222 · published 23 January 2024
CVE-2024-23222: Apple WebKit type confusion allows code execution via crafted web content
Apple · Safari
A type confusion flaw in Apple's WebKit engine was addressed with improved checks. Processing maliciously crafted web content can lead to arbitrary code execution, and the fix was shipped across Safari, iOS, iPadOS, macOS, tvOS and visionOS. The record notes the fix is associated with the Coruna exploit and was backported to older iOS versions that cannot update to the latest release.
Description
A type confusion issue was addressed with improved checks. This issue is fixed in Safari 17.3, iOS 15.8.7 and iPadOS 15.8.7, iOS 16.7.5 and iPadOS 16.7.5, iOS 17.3 and iPadOS 17.3, macOS Monterey 12.7.3, macOS Sonoma 14.3, macOS Ventura 13.6.4, tvOS 17.3, visionOS 1.0.2. Processing maliciously crafted web content may lead to arbitrary code execution. This fix associated with the Coruna exploit was shipped in iOS 17.3 on January 22, 2024. This update brings that fix to devices that cannot update to the latest iOS version.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Automated analysis
high priorityCVSS 8.8 with network reachability and known exploitation per CISA KEV, though it requires user interaction and no ransomware use is documented.
What it is
A type confusion flaw in Apple's WebKit engine was addressed with improved checks. Processing maliciously crafted web content can lead to arbitrary code execution, and the fix was shipped across Safari, iOS, iPadOS, macOS, tvOS and visionOS. The record notes the fix is associated with the Coruna exploit and was backported to older iOS versions that cannot update to the latest release.
Impact
An attacker can achieve arbitrary code execution in the context of the affected WebKit process, giving code execution on the victim device. The CVSS vector rates confidentiality, integrity and availability impact as high.
Attack surface
Reached over the network by rendering maliciously crafted web content; the CVSS vector requires user interaction (UI:R) and no privileges (PR:N), consistent with a victim visiting or being served a malicious page. No authentication is needed.
Exploitation
CVE-2024-23222 is listed in CISA KEV with a due date of 2024-02-13, indicating known exploitation; EPSS 30-day probability is about 10.6 percent (95.5th percentile). No ransomware campaign use is documented.
What to do
- Update to the fixed versions: Safari 17.3, iOS/iPadOS 17.3, iOS/iPadOS 16.7.5, iOS/iPadOS 15.8.7, macOS Sonoma 14.3, macOS Ventura 13.6.4, macOS Monterey 12.7.3, tvOS 17.3, visionOS 1.0.2.
- Prioritize patching internet-facing and user-facing Apple devices, especially those that cannot move to the newest OS and rely on the backported fixes.
- Enforce update compliance for Safari and WebKit-based clients and block or restrict use of unpatched versions where patching is not possible.
- Follow CISA KEV required action: apply vendor mitigations or discontinue use of the product if mitigations are unavailable.
Detection
- Monitor for crashes or abnormal behavior in WebKit processes (Safari, WebKit content processes) on unpatched Apple devices.
- Hunt for exploitation indicators around the Coruna exploit referenced in the advisory, including unusual outbound network activity from browser processes.
- Track asset inventory for Apple devices still running versions below the fixed releases listed in the advisory.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2024-23222 to the Known Exploited Vulnerabilities catalog on 23 January 2024 as "Apple Multiple Products WebKit Type Confusion Vulnerability". Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Federal deadline 13 February 2024.
Affected products
6 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2024-23222 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2024-23222), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.