CVE-2024-23225Disclosure(apple / ipados)

HIGHCVSS 7.8 · HIGHCISA KEV

Exploitation ongoing with high activity in latest observed window (2 mentions)

Immediate actions

  • Prioritize remediation for apple ipados systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: Immediate (within 24h)

NVD description

A memory corruption issue was addressed with improved validation. This issue is fixed in iOS 16.7.6 and iPadOS 16.7.6, iOS 17.4 and iPadOS 17.4, macOS Monterey 12.7.4, macOS Sonoma 14.4, macOS Ventura 13.6.5, tvOS 17.4, visionOS 1.1, watchOS 10.4. An attacker with arbitrary kernel read and write capability may be able to bypass kernel memory protections. Apple is aware of a report that this issue may have been exploited.

7.5/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2024-03-27. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Weakness type (CWE)
CWE-787

Priority

HIGH

Exploitation

ACTIVE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • ipados
  • iphone_os
  • macos
  • tvos

Threat summary

  • Active exploitation appears in 2 classified signals
  • Public PoC and exploit tooling are both present
  • 8 mentions across 5 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 2 signals
  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 1 signal
  • Technical details provided in 5 signals
  • Disclosure: 4 classified signals
  • General: 3 classified signals
  • Peaked 4d ago at 2 mentions (2026-03-04); latest day: 2
  • 8 total mentions across 5 days

Affected systems

Vendors
Products
ipadosiphone_osmacostvosvisionoswatchos

Deep dive

Activity timeline8 mentions / 5d
01122Mentions · 2026-03-04: 2Mentions · 2026-03-06: 1Mentions · 2026-03-07: 2Mentions · 2026-04-03: 1Mentions · 2026-05-04: 2PoC Mentioned / Linked · 2026-05-04: 1Exploit Tool / Code · 2026-05-04: 1Active Exploitation · 2026-04-03: 1Active Exploitation · 2026-05-04: 1Technical Details · 2026-03-04: 1Technical Details · 2026-03-06: 1Technical Details · 2026-03-07: 1Technical Details · 2026-04-03: 1Technical Details · 2026-05-04: 103-0403-0603-0704-0305-04
Signal classification3 categories
Disclosure
450.0%
General
337.5%
Active Exploitation
112.5%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-03-042
Disclosure1General1
2026-03-061
Disclosure1
2026-03-072
Disclosure1General1
2026-04-031
General1
2026-05-042
Active Exploitation1Disclosure1
Full discourse8 posts
  • Duy Tran@khanhduytran0
    Disclosure

    Google has identified the following CVEs as PPL bypasses (17.0+ only applies to A12-A14) CVE-2024-23225: 17.0-17.3 CVE-2024-23296: 17.1-17.4 16.5.1-16.7.8 are also vulnerable to plenty of PPL bypasses Also, some pages are still up! Archive them while you can since these can be later exploited for jailbreak and such.

    Post summary

    Google lists CVE-2024-23225 and CVE-2024-23296 as PPL bypass vulnerabilities affecting specific Android versions, but offers no PoC, exploit, patch, or evidence of active exploitation.

    122322187645.9K
    11.9K followersView on X
  • Md Ismail Šojal 🕷️@0x0SojalSec
    Disclosure

    Jailbreakers Are Smiling 🥹 The gold is in the PPL bypass PPL bypass CVEs confirmed vulnerable on 16.5+ & 17.x. CVE-2024-23225: iOS 17.0–17.3, CVE-2024-23296: 17.1–17.4 These CVEs Could Unlock iOS 17 Jailbreak tons on iOS 16 also has plenty.

    Post summary

    The post announces that PPL bypass CVEs (CVE-2024-23225 and CVE-2024-23296) are confirmed vulnerable on iOS 16.5+ and 17.x, potentially enabling jailbreaks, with no specific exploit code or patch discussed.

    1130995016.9K
    42.5K followersView on X
  • Hermes Tool@Hermes_tooll
    Disclosure

    PPL bypass CVEs confirmed vulnerable on 16.5+ & 17.x. CVE-2024-23225: iOS 17.0–17.3, CVE-2024-23296: 17.1–17.4 These CVEs Could Unlock iOS 17 Jailbreak tons on iOS 16 also has plenty.

    Post summary

    The post confirms that CVE‑2024‑23225 and CVE‑2024‑23296 affect iOS 16.5+ and various iOS 17 releases, potentially enabling jailbreaks, but offers no PoC, exploit details, patches, or evidence of active exploitation.

    771101178.9K
    2.1K followersView on X
  • ONE Jailbreak@onejailbreak_
    General

    @notboboor But yeah, it could be used for a jailbreak. iOS 17.0+ only applies to A12–A14 devices, and: - CVE-2024-23225: 17.0–17.3 - CVE-2024-23296: 17.1–17.4 and 16.5.1–16.7.8

    Post summary

    The tweet lists two CVEs that affect specific iOS versions and hints at jailbreak potential, but provides no exploitation code, patch information, or detailed technical data.

    00050627
    27.1K followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    CVE-2024-23225: Apple iOS, iPadOS, macOS, tvOS, watchOS, and visionOS kernel contain a memory corruption vulnerability that allows an attacker with arbitrary kernel read and write capability to bypass kernel memory protections.

    Post summary

    Apple’s CVE-2024-23225 is a newly disclosed kernel memory corruption flaw that permits arbitrary kernel read/write, enabling bypass of memory protections across all major Apple operating systems.

    1000054
    152 followersView on X
  • CVETrends@CVEShield
    General

    Top 5 Trending CVEs: 1 - CVE-2023-20198 2 - CVE-2023-50428 3 - CVE-2026-0757 4 - CVE-2024-23225 5 - CVE-2026-20700 #cve #cvetrends #cveshield #cybersecurity https://www.cveshield.com/dashboard

    Post summary

    The message lists five trending CVEs without providing any technical, exploit, or mitigation details.

    00010158
    1.7K followersView on X
  • Lyrie.ai@lyrie_ai
    Active Exploitation

    https://lyrie.ai/research/research/active-exploit-cve-2024-23225-multiple-products #lyrie #cybersecurity #CVE #threatintel #zerodayattack

    Post summary

    The linked research post reports that CVE-2024-23225 is actively exploited in the wild across multiple products, indicating a current threat landscape.

    0000025
    152 followersView on X
  • AiSoloStudio@aisolostudio
    General

    NVDでApple関連CVE 200件のメタデータ一斉更新。WebKit型混乱(CVE-2024-23222)やカーネルメモリ破壊(CVE-2024-23225/23296)など悪用確認済み3件含む。古いiOS/macOSを使い続けている場合は改めて確認を。 #セキュリティ #CVE #脆弱性 https://tsumikasane.net/security/daily/2026-04-03/

    Post summary

    Apple-related CVEs were updated on NVD, with 200 entries including three that have confirmed exploitation; users still on older iOS/macOS should verify vulnerability status.

    0000077
    4 followersView on X
CPE platform detail6 entries

6 of 6 entries

PartVendorProductVersionTarget SWTarget HW
OSappleipados---
OSappleiphone_os---
OSapplemacos---
OSappletvos---
OSapplevisionos---
OSapplewatchos---

Explore more