{
  "crds_version": "0.1",
  "kind": "base",
  "id": "crds:cve-2024-23296",
  "revision": 1,
  "title": "Apple RTKit — the second kernel loses its memory protections",
  "summary": "The real-time system Apple runs alongside the main kernel (RTKit) mishandles memory, so an attacker who already reads and writes kernel memory gets past the checks meant to contain that. Apple says it may have been exploited.",
  "source_type": "cve",
  "severity": "high",
  "cvss": {
    "score": 7.8,
    "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
    "version": "3.1"
  },
  "epss": 0.01411,
  "exploitation": {
    "known_exploited": true,
    "exploit_available": false,
    "attack_complexity": "low",
    "kev_added": "2024-03-06",
    "prerequisites": "The attacker must already hold arbitrary kernel read and write access."
  },
  "remediation": {
    "patch_available": true,
    "fixed_in": [
      "iOS 17.4",
      "iOS 16.7.8",
      "macOS Sonoma 14.4",
      "macOS Ventura 13.6.7",
      "macOS Monterey 12.7.6"
    ]
  },
  "mitre_attack": [
    "T1068"
  ],
  "kill_chain": "privilege_escalation",
  "recommended_action": "Update to iOS and iPadOS 17.4 or 16.7.8, macOS Sonoma 14.4, Ventura 13.6.7 or Monterey 12.7.6, plus the matching tvOS and watchOS releases.",
  "confidence": "high",
  "provenance": [
    {
      "fields": [
        "cvss",
        "exploitation.attack_complexity",
        "exploitation.exploit_available",
        "references",
        "published_at"
      ],
      "source": "https://nvd.nist.gov/vuln/detail/CVE-2024-23296",
      "retrieved_at": "2026-09-24T12:52:19.575Z",
      "confidence": "high",
      "extractor": "scrty-crds-pipeline/0.1"
    },
    {
      "fields": [
        "exploitation.known_exploited",
        "exploitation.kev_added"
      ],
      "source": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
      "retrieved_at": "2026-09-24T12:52:19.575Z",
      "confidence": "high",
      "extractor": "scrty-crds-pipeline/0.1"
    },
    {
      "fields": [
        "epss"
      ],
      "source": "https://api.first.org/data/v1/epss?cve=CVE-2024-23296",
      "retrieved_at": "2026-09-24T12:52:19.575Z",
      "confidence": "high",
      "extractor": "scrty-crds-pipeline/0.1"
    },
    {
      "fields": [
        "title",
        "summary",
        "severity",
        "remediation",
        "mitre_attack",
        "kill_chain",
        "recommended_action",
        "confidence",
        "tags",
        "exploitation.prerequisites"
      ],
      "source": "https://nvd.nist.gov/vuln/detail/CVE-2024-23296",
      "retrieved_at": "2026-09-24T12:52:19.575Z",
      "confidence": "high",
      "extractor": "claude-code"
    }
  ],
  "references": [
    {
      "type": "cve",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-23296",
      "label": "NVD record"
    },
    {
      "type": "cisa",
      "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
      "label": "CISA Known Exploited Vulnerabilities catalog"
    },
    {
      "type": "vendor_advisory",
      "url": "https://support.apple.com/en-us/120881"
    },
    {
      "type": "vendor_advisory",
      "url": "https://support.apple.com/en-us/120882"
    },
    {
      "type": "vendor_advisory",
      "url": "https://support.apple.com/en-us/120883"
    }
  ],
  "published_at": "2024-03-05T20:16:01.553Z",
  "issued_at": "2026-09-24T12:52:19.575Z",
  "tags": [
    "apple",
    "ios",
    "macos",
    "rtkit",
    "memory-corruption",
    "kev"
  ]
}
