ZeroHour

CVE-2024-44308

KEVmass

Arbitrary Code Execution via Crafted Web Content in Apple Safari, iOS, macOS and visionOS

CISA: Apple Multiple Products Code Execution Vulnerability

CVSS 3.1
8.8 high
EPSS
10%p95
Published
()
KEV added
AI analysis

CVE-2024-44308 is a code execution vulnerability in the web content processing engine used by Safari and Apple's operating systems, which Apple addressed with improved checks in emergency updates released in November 2024. It is triggered when a device processes maliciously crafted web content, for example when a user is lured to an attacker-controlled webpage, and requires user interaction (CVSS 3.1: AV:N/UI:R). Successful exploitation yields arbitrary code execution with high impact on confidentiality, integrity, and availability (CVSS 3.1 score 8.8). Users of Safari before 18.1.1, iOS and iPadOS before 17.7.2 and 18.1.1, macOS Sequoia before 15.1.1, and visionOS before 2.1.1 are affected; Debian Linux is also listed in the CPE data but no Debian-specific fix version was provided in the source. Apple reported active exploitation, specifically on Intel-based Mac systems, and CISA added the flaw to its Known Exploited Vulnerabilities catalog on 2024-11-21; EPSS assigns a 9.4% probability of exploitation within 30 days.

What to do: Immediately update to Safari 18.1.1, iOS/iPadOS 17.7.2 or 18.1.1, macOS Sequoia 15.1.1 and visionOS 2.1.1, prioritizing Intel-based Macs since confirmed exploitation was reported on those systems. Federal agencies must patch per CISA's KEV requirement (added 2024-11-21), and defenders should review unpatched Macs for signs of browser-based compromise. Debian users should monitor their vendor's advisory for a WebKit-related backport, as no fixed Debian version was specified in the source data.

Affected
Apple Safariversions prior to 18.1.1 (fixed in Safari 18.1.1)
Apple iOS (iPhone OS)versions prior to 17.7.2 and prior to 18.1.1 (fixed in iOS 17.7.2 and iOS 18.1.1)
Apple iPadOSversions prior to 17.7.2 and prior to 18.1.1 (fixed in iPadOS 17.7.2 and iPadOS 18.1.1)
Apple macOS (Sequoia)versions prior to 15.1.1 (fixed in macOS Sequoia 15.1.1)
Apple visionOSversions prior to 2.1.1 (fixed in visionOS 2.1.1)
Debian Linuxlisted in CPE data; no Debian-specific affected or fixed version specified in the source
Estimated exposure
masshundreds of millions to 1 billion+ users (Apple's global active device base across iPhone, iPad, Mac, Vision Pro and Safari) — Estimate is based on Apple's very large installed base of iOS/macOS/Safari devices worldwide, essentially all of which were vulnerable on the affected version branches until the November 2024 updates; no public internet-exposure scan…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

The issue was addressed with improved checks. This issue is fixed in Safari 18.1.1, iOS 17.7.2 and iPadOS 17.7.2, iOS 18.1.1 and iPadOS 18.1.1, macOS Sequoia 15.1.1, visionOS 2.1.1. Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited on Intel-based Mac systems.

CISA Known Exploited Vulnerability
Affected
Apple Multiple Products
Required action
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Due date
Ransomware use
Unknown
Vendors
debianapple
Products
debian linux, safari, ipados, iphone os, macos, visionos
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news