Apple Addresses Web Content Execution Vulnerability in Safari, macOS Sequoia, iOS, iPadOS, and visionOS

CVE-2024-44308
Currently unrated 🤨

Key Information

Vendor
Apple
Status
Safari
Mac OS
iOS And iPad OS
Visionos
Vendor
CVE Published:
20 November 2024

Badges

😄 Trended👾 Exploit Exists📰 News Worthy

Summary

The vulnerability CVE-2024-44308 has been addressed by Apple in Safari, macOS Sequoia, iOS, iPadOS, and visionOS. It is a web content execution vulnerability that could lead to arbitrary code execution. The issue has been fixed in various software versions, and Apple is aware of a report that it may have been actively exploited on Intel-based Mac systems. The vulnerability CVE-2024-44309 is another zero-day vulnerability in macOS Sequoia that has been exploited in the wild. It affects the WebKit browser engine and JavaScriptCore, potentially allowing for arbitrary code execution and cross-site scripting attacks. Apple has patched these vulnerabilities in various software versions to protect users. The potential impact of these vulnerabilities is severe, as they could be exploited to compromise systems and conduct targeted attacks.

CISA Reported

CISA provides regional cyber and physical services to support security and resilience across the United States. CISA monitor the most dangerious vulnerabilities and have identifed CVE-2024-44308 as being exploited but is not known by the CISA to be used in ransomware campaigns. This is subject to change at pace

The CISA's recommendation is: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Affected Version(s)

Safari < 18.1

macOS < 15.1

iOS and iPadOS < 18.1

News Articles

Timeline

  • Vulnerability started trending.

  • 👾

    Exploit exists.

  • First article discovered by Help Net Security

  • Vulnerability published.

Collectors

NVD DatabaseMitre DatabaseCISA Database4 News Article(s)
.