PT-2024-1204 · Apple+7 · Visionos+12
James Lee
+1
·
Published
2023-07-18
·
Updated
2026-03-16
·
CVE-2024-23222
CVSS v2.0
10
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
webkit2gtk versions prior to 2.42.5-0ubuntu0.22.04.2
webkit2gtk3 (affected versions not specified)
Apple products (affected versions not specified)
Description
The webkit2gtk and webkit2gtk3 engines contain a type confusion flaw. This issue is actively exploited and may allow an attacker to execute arbitrary code by tricking a user into viewing a malicious website. Apple has addressed this vulnerability in iOS 17.3 and iPadOS 17.3, macOS Sonoma 14.3, tvOS 17.3, iOS 16.7.5, iPadOS 16.7.5, and macOS Monterey 12.7.3. The vulnerability exists in WebKit, the browser engine used by Safari.
Recommendations
Update webkit2gtk to version 2.42.5-0ubuntu0.22.04.2 or later.
Update Apple products to the latest available versions, including iOS, iPadOS, macOS, and tvOS.
Exploit
Fix
Type Confusion
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Astra Linux
Centos
Debian
Linuxmint
Apple Macos
Red Hat
Suse
Ubuntu
Webkit
Ios
Ipados
Tvos
Visionos