NA

CVE-2024-23257

Published: 08/03/2024 Updated: 13/03/2024

Vulnerability Summary

This vulnerability allows remote malicious users to disclose sensitive information on affected installations of Apple macOS. Interaction with the ImageIO framework is required to exploit this vulnerability but attack vectors may vary depending on the implementation. The specific flaw exists within the ImageIO framework. Crafted data in a JP2 image can trigger access to a pointer prior to initialization. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of the current process.

Vendor Advisories

About Apple security updates For our customers' protection, Apple doesn't disclose, discuss, or confirm security issues until an investigation has occurred and patches or releases are available Recent releases are listed on the Apple security releases page Apple security documents reference vulnerabilities by CVE-ID whe ...
About Apple security updates For our customers' protection, Apple doesn't disclose, discuss, or confirm security issues until an investigation has occurred and patches or releases are available Recent releases are listed on the Apple security releases page Apple security documents reference vulnerabilities by CVE-ID whe ...
About Apple security updates For our customers' protection, Apple doesn't disclose, discuss, or confirm security issues until an investigation has occurred and patches or releases are available Recent releases are listed on the Apple security releases page Apple security documents reference vulnerabilities by CVE-ID whe ...
About Apple security updates For our customers' protection, Apple doesn't disclose, discuss, or confirm security issues until an investigation has occurred and patches or releases are available Recent releases are listed on the Apple security releases page Apple security documents reference vulnerabilities by CVE-ID whe ...

Mailing Lists

-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 APPLE-SA-03-07-2024-3 macOS Ventura 1365 macOS Ventura 1365 addresses the following issues Information about the security content is also available at supportapplecom/kb/HT214085 Apple maintains a Security Releases page at supportapplecom/HT201222 which lists recent softwa ...
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 APPLE-SA-03-07-2024-2 macOS Sonoma 144 macOS Sonoma 144 addresses the following issues Information about the security content is also available at supportapplecom/kb/HT214084 Apple maintains a Security Releases page at supportapplecom/HT201222 which lists recent software upd ...
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 APPLE-SA-03-07-2024-7 visionOS 11 visionOS 11 addresses the following issues Information about the security content is also available at supportapplecom/kb/HT214087 Apple maintains a Security Releases page at supportapplecom/HT201222 which lists recent software updates with ...
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 APPLE-SA-03-07-2024-4 macOS Monterey 1274 macOS Monterey 1274 addresses the following issues Information about the security content is also available at supportapplecom/kb/HT214083 Apple maintains a Security Releases page at supportapplecom/HT201222 which lists recent soft ...