Apple Security Updates – 23 January 2024

Apple has released security updates to address multiple vulnerabilities across macOS Monterey, Ventura, Sonoma, and Safari.

The addressed vulnerabilities could allow the attacker to bypass security restrictions, gain elevated privileges, obtain sensitive information, execute arbitrary code, and gain access to the affected systems by persuading the victim
to visit a specially crafted website.

Sample of the addressed vulnerabilities:

1. Apple macOS Code Execution Vulnerability (CVE-2024-23222):

  • CVSS: 8.8
  • Attack Vector: Network
  • Attack Complexity: Low
  • Privileges Required: None
  • User Interaction: Required
  • Consequences: Gain Access

2. Apple macOS Sonoma Privilege Escalation Vulnerability (CVE-2024-23208):

  • CVSS: 7.8
  • Attack Vector: Local
  • Attack Complexity: Low
  • Privileges Required: None
  • User Interaction: Required
  • Consequences: Gain Privileges

It should be highlighted that Apple is aware that a public exploit for the zero-day vulnerability “CVE-2024-23222” exists in the wild.

Vulnerabilities
Mitigations

The enterprise should deploy this patch as soon as the testing phase is completed.

Apple Security Advisory

References