PT-2024-1204 · Apple+7 · Webkit+12

James Lee

+1

·

Published

2023-07-18

·

Updated

2025-09-29

·

CVE-2024-23222

CVSS v2.0
10
VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions webkit2gtk versions prior to 2.42.5-0ubuntu0.22.04.2 webkit2gtk3 (affected versions not specified) Apple products (affected versions not specified)
Description The webkit2gtk and webkit2gtk3 engines contain a type confusion flaw. This issue is actively exploited and may allow an attacker to execute arbitrary code by tricking a user into viewing a malicious website. Apple has addressed this vulnerability in iOS 17.3 and iPadOS 17.3, macOS Sonoma 14.3, tvOS 17.3, iOS 16.7.5, iPadOS 16.7.5, and macOS Monterey 12.7.3. The vulnerability exists in WebKit, the browser engine used by Safari.
Recommendations Update webkit2gtk to version 2.42.5-0ubuntu0.22.04.2 or later. Update Apple products to the latest available versions, including iOS, iPadOS, macOS, and tvOS.

Exploit

Fix

Type Confusion

Weakness Enumeration

Related Identifiers

BDU:2024-00584
CESA-2023_4202
CVE-2024-23222
DSA-5618-1
MGASA-2024-0148
OPENSUSE-SU-2024_0548-1
OPENSUSE-SU-2024_3752-1
OPENSUSE-SU-2024_3869-1
RHSA-2023:4201
RHSA-2023:4202
RHSA-2023_4201
RHSA-2023_4202
RHSA-2024:8496
RHSA-2024:9638
RHSA-2024:9653
RHSA-2024:9679
RHSA-2024:9680
RHSA-2025:10364
SUSE-SU-2024:0301-1
SUSE-SU-2024:0519-1
SUSE-SU-2024:0545-1
SUSE-SU-2024:0548-1
SUSE-SU-2024:3752-1
SUSE-SU-2024:3869-1
SUSE-SU-2024:3870-1
SUSE-SU-2024_0301-1
USN-6631-1

Affected Products

Astra Linux
Centos
Debian
Linuxmint
Apple Macos
Red Hat
Suse
Ubuntu
Webkit
Ios
Ipados
Tvos
Visionos