CVE-2024-23296Disclosure(apple / ipados)

MEDIUMCVSS 7.8 · HIGHCISA KEV

Exploitation ongoing with high activity in latest observed window (2 mentions)

Immediate actions

  • Patch apple ipados systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

A memory corruption issue was addressed with improved validation. This issue is fixed in iOS 16.7.8 and iPadOS 16.7.8, iOS 17.4 and iPadOS 17.4, macOS Monterey 12.7.6, macOS Sonoma 14.4, macOS Ventura 13.6.7, tvOS 17.4, visionOS 1.1, watchOS 10.4. An attacker with arbitrary kernel read and write capability may be able to bypass kernel memory protections. Apple is aware of a report that this issue may have been exploited.

4.5/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2024-03-27. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Weakness type (CWE)
CWE-787

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • ipados
  • iphone_os
  • macos
  • tvos

Threat summary

  • Active exploitation appears in 2 classified signals
  • Patch or workaround signal is available
  • 6 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 2 signals
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 3 classified signals
  • General: 1 classified signal
  • Peaked 3d ago at 2 mentions (2026-03-04); latest day: 2
  • 6 total mentions across 4 days

Affected systems

Vendors
Products
ipadosiphone_osmacostvosvisionoswatchos

Deep dive

Activity timeline6 mentions / 4d
01122Mentions · 2026-03-04: 2Mentions · 2026-03-06: 1Mentions · 2026-03-07: 1Mentions · 2026-05-04: 2Active Exploitation · 2026-05-04: 2Patch / Workaround · 2026-05-04: 1Technical Details · 2026-03-04: 1Technical Details · 2026-03-07: 103-0403-0603-0705-04
Signal classification3 categories
Disclosure
350.0%
Active Exploitation
233.3%
General
116.7%
Referenced assets1 URL
Classification over time
DateTotalLabels
2026-03-042
Disclosure1General1
2026-03-061
Disclosure1
2026-03-071
Disclosure1
2026-05-042
Active Exploitation2
Full discourse6 posts
  • Duy Tran@khanhduytran0
    Disclosure

    Google has identified the following CVEs as PPL bypasses (17.0+ only applies to A12-A14) CVE-2024-23225: 17.0-17.3 CVE-2024-23296: 17.1-17.4 16.5.1-16.7.8 are also vulnerable to plenty of PPL bypasses Also, some pages are still up! Archive them while you can since these can be later exploited for jailbreak and such.

    Post summary

    Google disclosed CVE-2024-23225 and CVE-2024-23296 as PPL bypasses affecting Android 17.0‑17.4 (with specific version ranges), noted that older versions 16.5.1‑16.7.8 are also vulnerable, and warned that still‑active pages could be exploited later for jailbreak.

    122322187645.9K
    11.9K followersView on X
  • Md Ismail Šojal 🕷️@0x0SojalSec
    Disclosure

    Jailbreakers Are Smiling 🥹 The gold is in the PPL bypass PPL bypass CVEs confirmed vulnerable on 16.5+ & 17.x. CVE-2024-23225: iOS 17.0–17.3, CVE-2024-23296: 17.1–17.4 These CVEs Could Unlock iOS 17 Jailbreak tons on iOS 16 also has plenty.

    Post summary

    The post announces two PPL bypass CVEs (CVE-2024-23225 and CVE-2024-23296) that affect iOS 16.5+ and iOS 17.x, implying potential jailbreak capability, but offers no technical details, PoC, or exploit evidence.

    1130995016.9K
    42.5K followersView on X
  • Hermes Tool@Hermes_tooll
    Disclosure

    PPL bypass CVEs confirmed vulnerable on 16.5+ & 17.x. CVE-2024-23225: iOS 17.0–17.3, CVE-2024-23296: 17.1–17.4 These CVEs Could Unlock iOS 17 Jailbreak tons on iOS 16 also has plenty.

    Post summary

    Two iOS 17 CVEs (CVE-2024-23225, CVE-2024-23296) are confirmed vulnerable on iOS 16.5+ and 17.x, potentially enabling jailbreaks.

    771101178.9K
    2.1K followersView on X
  • ONE Jailbreak@onejailbreak_
    General

    @notboboor But yeah, it could be used for a jailbreak. iOS 17.0+ only applies to A12–A14 devices, and: - CVE-2024-23225: 17.0–17.3 - CVE-2024-23296: 17.1–17.4 and 16.5.1–16.7.8

    Post summary

    The message cites two iOS CVEs that could facilitate jailbreaking but provides neither a PoC nor any exploitation details.

    00050627
    27.1K followersView on X
  • Lyrie.ai@lyrie_ai
    Active Exploitation

    00:00 UTC: CVE-2024-23296 disclosed. CISA: CVE-2024-23296 added to Known Exploited Vulnerabilities — Apple Multiple Products Status: ✅ Confirmed exploited in the wild Date added: 2024-03-06 Required action: Apply mitigations per vendor instructions or discontinue use of…

    Post summary

    CVE‑2024‑23296 has been confirmed as exploited in the wild; users are advised to apply vendor mitigation measures or stop using the affected products.

    1000045
    152 followersView on X
  • Lyrie.ai@lyrie_ai
    Active Exploitation

    https://lyrie.ai/research/research/active-exploit-cve-2024-23296-multiple-products #lyrie #cybersecurity #CVE #threatintel #zerodayattack

    Post summary

    The entry signals that CVE‑2024‑23296 is being actively exploited across multiple products, as inferred from the URL, but lacks concrete PoC, exploit code, or patch information.

    0000024
    152 followersView on X
CPE platform detail6 entries

6 of 6 entries

PartVendorProductVersionTarget SWTarget HW
OSappleipados---
OSappleiphone_os---
OSapplemacos---
OSappletvos---
OSapplevisionos---
OSapplewatchos---

Explore more