
CVE-2024-23273 – Apple Security Advisory 03-07-2024-2
https://notcve.org/view.php?id=CVE-2024-23273
08 Mar 2024 — This issue was addressed through improved state management. This issue is fixed in Safari 17.4, iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4. Private Browsing tabs may be accessed without authentication. Esta cuestión se abordó mediante una mejor gestión de estado. Este problema se solucionó en Safari 17.4, iOS 17.4 y iPadOS 17.4, macOS Sonoma 14.4. • http://seclists.org/fulldisclosure/2024/Mar/20 • CWE-295: Improper Certificate Validation •

CVE-2024-23272 – Apple Security Advisory 03-07-2024-2
https://notcve.org/view.php?id=CVE-2024-23272
08 Mar 2024 — A logic issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14.4, macOS Monterey 12.7.4, macOS Ventura 13.6.5. A user may gain access to protected parts of the file system. Se solucionó un problema de lógica con controles mejorados. Este problema se solucionó en macOS Sonoma 14.4, macOS Monterey 12.7.4, macOS Ventura 13.6.5. • http://seclists.org/fulldisclosure/2024/Mar/21 •

CVE-2024-23268 – Apple Security Advisory 03-07-2024-2
https://notcve.org/view.php?id=CVE-2024-23268
08 Mar 2024 — An injection issue was addressed with improved input validation. This issue is fixed in macOS Sonoma 14.4, macOS Monterey 12.7.4, macOS Ventura 13.6.5. An app may be able to elevate privileges. Se solucionó un problema de inyección con una validación de entrada mejorada. Este problema se solucionó en macOS Sonoma 14.4, macOS Monterey 12.7.4, macOS Ventura 13.6.5. • http://seclists.org/fulldisclosure/2024/Mar/21 • CWE-74: Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') CWE-75: Failure to Sanitize Special Elements into a Different Plane (Special Element Injection) •

CVE-2024-23267 – Apple Security Advisory 03-07-2024-2
https://notcve.org/view.php?id=CVE-2024-23267
08 Mar 2024 — The issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14.4, macOS Monterey 12.7.4, macOS Ventura 13.6.5. An app may be able to bypass certain Privacy preferences. El problema se solucionó con controles mejorados. Este problema se solucionó en macOS Sonoma 14.4, macOS Monterey 12.7.4, macOS Ventura 13.6.5. • http://seclists.org/fulldisclosure/2024/Mar/21 • CWE-284: Improper Access Control •

CVE-2024-23266 – Apple Security Advisory 03-07-2024-2
https://notcve.org/view.php?id=CVE-2024-23266
08 Mar 2024 — The issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14.4, macOS Monterey 12.7.4, macOS Ventura 13.6.5. An app may be able to modify protected parts of the file system. El problema se solucionó con controles mejorados. Este problema se solucionó en macOS Sonoma 14.4, macOS Monterey 12.7.4, macOS Ventura 13.6.5. • http://seclists.org/fulldisclosure/2024/Mar/21 • CWE-284: Improper Access Control •

CVE-2024-23270 – Apple Security Advisory 03-07-2024-2
https://notcve.org/view.php?id=CVE-2024-23270
08 Mar 2024 — The issue was addressed with improved memory handling. This issue is fixed in macOS Monterey 12.7.4, macOS Ventura 13.6.5, macOS Sonoma 14.4, iOS 17.4 and iPadOS 17.4, tvOS 17.4. An app may be able to execute arbitrary code with kernel privileges. El problema se solucionó mejorando el manejo de la memoria. Este problema se solucionó en macOS Monterey 12.7.4, macOS Ventura 13.6.5, macOS Sonoma 14.4, iOS 17.4 y iPadOS 17.4, tvOS 17.4. • http://seclists.org/fulldisclosure/2024/Mar/21 • CWE-787: Out-of-bounds Write •

CVE-2024-23277 – Apple Security Advisory 03-07-2024-2
https://notcve.org/view.php?id=CVE-2024-23277
08 Mar 2024 — The issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14.4, iOS 17.4 and iPadOS 17.4. An attacker in a privileged network position may be able to inject keystrokes by spoofing a keyboard. El problema se solucionó con controles mejorados. Este problema se solucionó en macOS Sonoma 14.4, iOS 17.4 y iPadOS 17.4. • http://seclists.org/fulldisclosure/2024/Mar/21 •

CVE-2024-23276 – Apple Security Advisory 03-07-2024-2
https://notcve.org/view.php?id=CVE-2024-23276
08 Mar 2024 — A logic issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14.4, macOS Monterey 12.7.4, macOS Ventura 13.6.5. An app may be able to elevate privileges. Se solucionó un problema de lógica con controles mejorados. Este problema se solucionó en macOS Sonoma 14.4, macOS Monterey 12.7.4, macOS Ventura 13.6.5. • http://seclists.org/fulldisclosure/2024/Mar/21 • CWE-269: Improper Privilege Management •

CVE-2024-23296 – Apple Multiple Products Memory Corruption Vulnerability
https://notcve.org/view.php?id=CVE-2024-23296
05 Mar 2024 — A memory corruption issue was addressed with improved validation. This issue is fixed in iOS 17.4 and iPadOS 17.4. An attacker with arbitrary kernel read and write capability may be able to bypass kernel memory protections. Apple is aware of a report that this issue may have been exploited. Se solucionó un problema de corrupción de memoria con una validación mejorada. • http://seclists.org/fulldisclosure/2024/Mar/18 • CWE-787: Out-of-bounds Write •

CVE-2024-23225 – Apple Multiple Products Memory Corruption Vulnerability
https://notcve.org/view.php?id=CVE-2024-23225
05 Mar 2024 — A memory corruption issue was addressed with improved validation. This issue is fixed in iOS 16.7.6 and iPadOS 16.7.6, iOS 17.4 and iPadOS 17.4. An attacker with arbitrary kernel read and write capability may be able to bypass kernel memory protections. Apple is aware of a report that this issue may have been exploited. Se solucionó un problema de corrupción de memoria con una validación mejorada. • http://seclists.org/fulldisclosure/2024/Mar/18 • CWE-787: Out-of-bounds Write •