CVE-2024-23222
ENISA EUVD: EUVD-2024-20741 ↗
Exploited in the Wild
✓ Confirmed 0-Day
★ Google Project Zero
Triaged: March 3, 2026
8 articles
EPSS Score
Source: FIRST.org · 2026-05-24
0.91%
probability
This CVE has a 0.91% probability
of being exploited in the next 30 days.
0%
Top 76.1th percentile of all CVEs
100%
CVSS v3.1
Source: NVD8.8
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Description
Project ZeroType confusion
Affected Products
Attack Intelligence
Google Project Zero
Patched
Jan. 22, 2024
Reported by
???
Root Cause Analysis
???
Exploits & PoC
FuzzySecurity/Cassowary-CVE-2024-23222-x86_64
Adaptation of Cassowary CVE-2024-23222 for Linux x86_64
10
Rohitberiwala/CVE-2024-23222-Coruna-Exploit-Kit-Deobfuscated
Comprehensive deobfuscated research of the Coruna iOS exploit kit targeting CVE-2024-23222. Analysis of WebKit Type Confusion, PAC Bypass, and Sandbox
3
Meysamshiralii/coruna_analysis
Analyze and deobfuscate the Coruna Exploit Kit (CVE-2024-23222) to enhance understanding and detection of related threats.
1
3 repos — triés par ⭐
Rechercher sur GitHub ↗
Apple fixes this year’s first actively exploited zero-day bug
BleepingComputer
Jan 27, 2025
Apple fixes first zero-day bug exploited in attacks this year
BleepingComputer
Jan 22, 2024
Apple Fixes WebKit Vulnerability Enabling Same-Origin Policy Bypass on iOS and macOS
TheHackerNews
Mar 18, 2026
Apple backports fix for zero-day exploited in attacks to older iPhones
BleepingComputer
May 13, 2024
Apple Issues Security Updates for Older iOS Devices Targeted by Coruna WebKit Exploit
TheHackerNews
Mar 12, 2026
Security Advisory 2024-013
CERT-EU
Jan 24, 2024
Signal Intelligence
Confidence
92%
EPSS
0.91%
CVSS v3.1
8.8
Mentions
8
Last Seen
Mar 18, 2026
CNA Information
Analyst Note
This CVE merits confirmed status due to multiple corroborating indicators: Apple explicitly acknowledged active exploitation in the wild, it is tracked by Google Project Zero, and multiple credible sources (BleepingComputer, CERT-EU) independently reported its active exploitation. The high CVSS score (8.8) combined with demonstrated real-world attacks in 2024 provides strong evidence of confirmation.
Threat Actors 10
MuddyWater
apt_group
Information theft and espionage
🇮🇷 IR
Lazarus Group
apt_group
Information theft and espionage
🇰🇵 KP
Cobalt
apt_group
Financial crime
🇷🇺 RU
APT37
apt_group
Information theft and espionage
🇰🇵 KP
Kimsuky
apt_group
Information theft and espionage
🇰🇷 KR
CHRYSENE
apt_group
Information theft and espionage
🇮🇷 IR
UAC-0020
apt_group
🇺🇦 UA
SideWinder
apt_group
🇮🇳 IN
RAZOR TIGER
apt_group
Information theft and espionage
🇮🇳 IN
Larva-208
apt_group
🇷🇺 RU
Triage Info
Decided atMar 03, 2026