CVE-2024-23222Active Exploitation(apple / ipados)

CRITICALCVSS 8.8 · HIGHCISA KEV

Exploitation observed; activity peaked at 3 mentions and remains active

Immediate actions

  • Patch apple ipados systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

A type confusion issue was addressed with improved checks. This issue is fixed in Safari 17.3, iOS 15.8.7 and iPadOS 15.8.7, iOS 16.7.5 and iPadOS 16.7.5, iOS 17.3 and iPadOS 17.3, macOS Monterey 12.7.3, macOS Sonoma 14.3, macOS Ventura 13.6.4, tvOS 17.3, visionOS 1.0.2. Processing maliciously crafted web content may lead to arbitrary code execution. This fix associated with the Coruna exploit was shipped in iOS 17.3 on January 22, 2024. This update brings that fix to devices that cannot update to the latest iOS version.

8.3/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2024-02-13. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Weakness type (CWE)
CWE-843

Priority

CRITICAL

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • ipados
  • iphone_os
  • macos
  • safari

Threat summary

  • Active exploitation appears in 6 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 16 mentions across 10 observed days

What's happening

  • Active exploitation reported across 6 signals
  • Exploit tool or code specified in 2 signals
  • PoC mentioned or linked in 2 signals
  • Patch or workaround mentioned in 6 signals
  • Technical details provided in 6 signals
  • General: 3 classified signals
  • Peaked 9d ago at 3 mentions (2026-03-05); latest day: 1
  • 16 total mentions across 10 days

Affected systems

Vendors
Products
ipadosiphone_osmacossafaritvosvisionos

Deep dive

Activity timeline16 mentions / 10d
01223Mentions · 2026-03-05: 3Mentions · 2026-03-11: 1Mentions · 2026-03-12: 2Mentions · 2026-03-13: 2Mentions · 2026-03-14: 2Mentions · 2026-03-15: 1Mentions · 2026-03-18: 1Mentions · 2026-04-03: 1Mentions · 2026-05-04: 2Mentions · 2026-05-22: 1PoC Mentioned / Linked · 2026-03-13: 2Exploit Tool / Code · 2026-03-12: 1Exploit Tool / Code · 2026-03-13: 1Active Exploitation · 2026-03-05: 2Active Exploitation · 2026-03-18: 1Active Exploitation · 2026-04-03: 1Active Exploitation · 2026-05-04: 1Active Exploitation · 2026-05-22: 1Patch / Workaround · 2026-03-05: 2Patch / Workaround · 2026-03-11: 1Patch / Workaround · 2026-03-12: 2Patch / Workaround · 2026-03-14: 1Technical Details · 2026-03-05: 2Technical Details · 2026-03-18: 1Technical Details · 2026-04-03: 1Technical Details · 2026-05-04: 1Technical Details · 2026-05-22: 103-0503-1103-1203-1303-1403-1503-1804-0305-0405-22
Signal classification5 categories
Active Exploitation
637.5%
Patch
425.0%
General
318.8%
PoC
212.5%
Disclosure
16.3%
Referenced assets9 URLs
Classification over time
DateTotalLabels
2026-03-053
Active Exploitation2General1
2026-03-111
Patch1
2026-03-122
Patch2
2026-03-132
PoC2
2026-03-142
General1Patch1
2026-03-151
General1
2026-03-181
Active Exploitation1
2026-04-031
Active Exploitation1
2026-05-042
Active Exploitation1Disclosure1
2026-05-221
Active Exploitation1
Full discourse16 posts
  • b33f | 🇺🇦✊@FuzzySec
    PoC

    I am releasing a reconstructed version of the cassowary CVE (CVE-2024-23222) that was disclosed as part of the Coruna leak. I also did some research with my AI assistants 😄 to reproduce a crash for the bug on x86_64 Linux https://github.com/FuzzySecurity/Cassowary-CVE-2024-23222-x86_64

    Post summary

    The author releases a reconstructed Proof‑of‑Concept repo for CVE‑2024‑23222, showing a crash on x86_64 Linux, but no exploit tool, active exploitation, or patch details are discussed.

    216081379.2K
    33.0K followersView on X
  • johnny@zeroxjf
    Patch

    @burhangee 16.7.9 is likely too high — the WebKit exploit CVE-2024-23222 was patched in 16.7.5. You would need 16.7.4 or lower for that stage to work

    Post summary

    The tweet indicates that WebKit CVE‑2024‑23222 was fixed in version 16.7.5, meaning older releases (16.7.4 or earlier) remain vulnerable.

    20030586
    2.0K followersView on X
  • CVETrends@CVEShield
    General

    Top 5 Trending CVEs: 1 - CVE-2024-23222 2 - CVE-2023-41993 3 - CVE-2025-64755 4 - CVE-2025-43300 5 - CVE-2026-3910 #cve #cvetrends #cveshield #cybersecurity https://www.cveshield.com/dashboard

    Post summary

    The post simply lists the top 5 trending CVEs without providing details on exploitation, mitigation, or vulnerability specifics.

    00031347
    1.7K followersView on X
  • Grok@grok
    Active Exploitation

    Hey boss, Coruna chain: JS on fake crypto/gambling site fingerprints iOS/version (no Lockdown), drops WebKit RCE in WebContent (e.g. CVE-2024-23222 type confusion) for code exec. Then PAC bypass (breezy/seedbell), sandbox esc (Iron/NeuronLoader), LPE (Neutron/Photon/Gruber) + PPL bypass to kernel root. No new spawned proc—injects PlasmaLoader stager into powerd (root daemon) for persistence, then CorePayload into locationd. Hooks modules into SpringBoard/imagent/Whatsapp for photo/notes/crypto exfil. EoP: web sandbox → root/kernel full control. Findings (Google/iVerify Mar '26): 5 chains/23 vulns (mix pub/non-pub), prolif from surveillance vendor → Russian APT (Ukraine watering holes) → Chinese crime (mass crypto theft). Patched >17.2.1. Update!

    Post summary

    The post details a multi‑stage exploit chain involving WebKit RCE (CVE‑2024‑23222) that has been used in real‑world attacks by Russian APTs and Chinese crime groups, and notes that a patch is available in iOS 17.2.1.

    10010119
    8.4M followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    CVE-2024-23222: Apple iOS, iPadOS, macOS, tvOS, and Safari WebKit contain a type confusion vulnerability that leads to code execution when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use WebKit, including but not limited to…

    Post summary

    Apple disclosed a type‑confusion vulnerability in WebKit on iOS, iPadOS, macOS, tvOS, and Safari that can lead to code execution via malicious web content.

    1000051
    152 followersView on X
  • Aviatrix Threat Research Center@aviatrixtrc
    Active Exploitation

    Attackers are chaining WebKit exploits with sandbox escapes to achieve kernel-level access on iOS devices. TRC analysis shows DarkSword uses CVE-2024-23222 and CVE-2023-32409 for initial compromise, then escalates privileges to exfiltrate passwords and crypto wallets. #MobileSecurity 🔗 Full breakdown: https://aviatrix.ai/threat-research-center/darksword-ios-exploit-kit-2026

    Post summary

    The report details DarkSword’s active use of WebKit sandbox escape vulnerabilities (CVE‑2024‑23222 & CVE‑2023‑32409) on iOS devices to acquire kernel‑level access and exfiltrate credentials and crypto wallets, with no mention of patches or PoC code.

    00001144
    1.9K followersView on X
  • CVETrends@CVEShield
    General

    Top 5 Trending CVEs: 1 - CVE-2026-25253 2 - CVE-2024-23222 3 - CVE-2026-3909 4 - CVE-2026-21643 5 - CVE-2026-2636 #cve #cvetrends #cveshield #cybersecurity https://www.cveshield.com/dashboard

    Post summary

    A social media update lists five trending CVEs without providing any additional information about exploitation, patches, or technical details.

    00010160
    1.7K followersView on X
  • b33f | 🇺🇦✊@FuzzySec
    PoC

    @roddux Like this https://github.com/FuzzySecurity/Cassowary-CVE-2024-23222-x86_64/blob/main/cassowary-CVE-2024-23222/yAerzw_d6cb72f5_analytic_rewrite.js

    Post summary

    The tweet links to a repository that presumably contains a proof‑of‑concept exploit for CVE‑2024‑23222, providing evidence of the PoC but no details on exploitation or mitigation.

    0000183
    33.0K followersView on X
  • Cybersecurity News Everyday@TweetThreatNews
    Patch

    Apple has released security patches for older iPhones and iPads to fix kernel and WebKit vulnerabilities exploited by the Coruna exploit kit, addressing multiple CVEs including CVE-2023-41974 and CVE-2024-23222. #Coruna #ExploitPatch #USA https://ift.tt/kfDTQAt

    Post summary

    Apple has released patches for older iPhones and iPads to address kernel and WebKit vulnerabilities (CVE-2023-41974 and CVE-2024-23222) that were exploited by the Coruna exploit kit.

    00010214
    3.7K followersView on X
  • kawn@kawn2020
    Patch

    #AppleUpdate #iOS #iPadOS iOS 15.8.7 および iPadOS 15.8.7 ・CVE-2024-23222 「This fix associated with the Coruna exploit was shipped in iOS 17.3 on January 22, 2024.」 対象は,iPhone 6s (全モデル), iPhone 7 (全モデル), iPhone SE (第 1 世代), iPad Air 2, iPad mini (第 4 世代)…

    Post summary

    The post announces that a patch for CVE-2024-23222 was delivered in iOS 17.3, referencing the Coruna exploit, without providing additional technical details or evidence of active exploitation.

    10000209
    89 followersView on X
  • CVETrends@CVEShield
    General

    Top 5 Trending CVEs: 1 - CVE-2024-23222 2 - CVE-2026-22719 3 - CVE-2026-25611 4 - CVE-2025-38617 5 - CVE-2026-21902 #cve #cvetrends #cveshield #cybersecurity https://www.cveshield.com/dashboard

    Post summary

    The post merely enumerates five trending CVEs without providing any additional technical, exploit, or mitigation information.

    00010232
    1.7K followersView on X
  • Grok@grok
    Active Exploitation

    Un site web infecte via "watering hole" : visite d'une page piégée (ex. fake crypto site) charge du JS qui fingerprint l'iPhone (iOS 13-17.2.1, Safari/WebKit). Exploits WebKit RCE (ex. CVE-2024-23222) → code natif dans WebContent → bypass PAC/sandbox → élévation kernel (ex. Photon/Parallax) → bypass PPL → injection dans démons root (powerd → locationd). Accès attaquant : root persistant, hook apps (wallets MetaMask etc.), vol photos/notes/QR/seeds crypto. Implant se connecte C2 HTTPS (AES chiffré), exfiltre et reçoit modules. Patches Apple depuis iOS 17.3+ bloquent tout. Lockdown Mode protège. Sources : Google GTIG & iVerify.

    Post summary

    The post details a watering‑hole attack exploiting WebKit RCE CVE‑2024‑23222 to achieve root on iOS, with Apple’s 17.3+ patches and Lockdown Mode listed as mitigations.

    10000143
    8.4M followersView on X
  • ThreadLinqs@threadlinqs
    Active Exploitation

    NEW THREAT INTEL: art-template npm hijack - Coruna iOS Safari watering-hole kit (CVE-2024-23222). 9 detections, 26 IOCs. https://intel.threadlinqs.com/#TL-2026-0568 #ThreatIntel #SupplyChain #npm https://t.co/8Q6299pJi0

    Post summary

    The post alerts on active exploitation of CVE-2024-23222 via an art-template npm hijack used in a watering‑hole attack against iOS Safari, with multiple detections and IOCs reported.

    00000101
    51 followersView on X
  • Lyrie.ai@lyrie_ai
    Active Exploitation

    https://lyrie.ai/research/research/active-exploit-cve-2024-23222-multiple-products #lyrie #cybersecurity #CVE #threatintel #zerodayattack

    Post summary

    The post indicates that CVE‑2024‑23222 is being actively exploited across multiple products, though no PoC, exploit code, patch, or technical details are disclosed.

    0000033
    152 followersView on X
  • AiSoloStudio@aisolostudio
    Active Exploitation

    NVDでApple関連CVE 200件のメタデータ一斉更新。WebKit型混乱(CVE-2024-23222)やカーネルメモリ破壊(CVE-2024-23225/23296)など悪用確認済み3件含む。古いiOS/macOSを使い続けている場合は改めて確認を。 #セキュリティ #CVE #脆弱性 https://tsumikasane.net/security/daily/2026-04-03/

    Post summary

    The NVD has updated metadata for 200 Apple‑related CVEs, noting that three (CVE‑2024‑23222, ‑23225, ‑23296) have confirmed exploitation, and advises users of older iOS/macOS to verify fixes.

    0000077
    4 followersView on X
  • Christina Ayiotis, Esq., CRM, CIPP/E, AIGP@christinayiotis
    Patch

    "patched .. underlying vulnerabilities in iOS updates .. over .. 2 years .. fixes for users who cannot update ..latest version. Specifically, iOS and iPadOS 15.8.7 patch 4 vulnerabilities: CVE-2023-41974, CVE-2024-23222, CVE-2023-43000, and CVE-2023-43010" https://www.securityweek.com/apple-updates-older-ios-versions-to-patch-coruna-exploits/

    Post summary

    The statement announces that Apple has released patches for four CVEs in iOS and iPadOS, indicating that a vendor-compliant fix is available.

    00000133
    3.5K followersView on X
CPE platform detail6 entries

6 of 6 entries

PartVendorProductVersionTarget SWTarget HW
OSappleipados---
OSappleiphone_os---
OSapplemacos---
Appapplesafari---
OSappletvos---
OSapplevisionos---

Explore more