CVE-2024-44309
KEVmass1Actively Exploited XSS in Apple WebKit Web Content Handling (iOS, iPadOS, macOS)
CISA: Apple Multiple Products Cross-Site Scripting (XSS) Vulnerability
CVE-2024-44309 is a cross-site scripting flaw (CWE-79) in how Apple's WebKit engine processes maliciously crafted web content on iOS, iPadOS, macOS, and other WebKit-based Apple products; Apple's advisories describe it as a cookie-management issue addressed with improved handling. An attacker triggers it by getting a user's browser or an app's embedded web view to load crafted web content, which allows script to run in the context of the targeted site — for example, reading or tampering with cookies and hijacking sessions. Any unpatched iPhone, iPad, or Mac — including users of Safari and third-party apps that render web content via Apple's web views — is in scope, and CISA's affected-product list is broad ('Apple Multiple Products'). The flaw is confirmed exploited in the wild: it was added to CISA's KEV on 2024-11-21 (ransomware use unknown), and EPSS assigns a 22.6% probability of exploitation within 30 days (98th percentile), although no public PoC is known. Fixes shipped in Apple's November 2024 security updates.
What to do: Patch promptly per the KEV-required action: upgrade to iOS/iPadOS 18.1.1 (or iOS/iPadOS 17.7.2 on the 17 branch) and macOS Sequoia 15.1.1, applying the matching Safari/WebKit updates for older macOS versions still in support. Until patched, treat untrusted links opened in Safari or in-app web views on Apple devices as a risk, and use MDM/patch inventories to confirm WebKit updates are installed fleet-wide.
| Apple iOS (WebKit web content processing) | Versions prior to iOS 18.1.1, and the iOS 17 branch prior to 17.7.2 (fixed per Apple's November 2024 advisories) |
| Apple iPadOS (WebKit web content processing) | Versions prior to iPadOS 18.1.1, and the iPadOS 17 branch prior to 17.7.2 (fixed per Apple's November 2024 advisories) |
| Apple macOS (WebKit web content processing) | macOS Sequoia versions prior to 15.1.1 (fixed per Apple's November 2024 advisories) |
| Apple Other WebKit-based Apple products (CISA lists 'Multiple Products'; e.g., Safari and apps embedding Apple web views) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
A cookie management issue was addressed with improved state management. This issue is fixed in Safari 18.1.1, iOS 17.7.2 and iPadOS 17.7.2, iOS 18.1.1 and iPadOS 18.1.1, macOS Sequoia 15.1.1, visionOS 2.1.1. Processing maliciously crafted web content may lead to a cross site scripting attack. Apple is aware of a report that this issue may have been actively exploited on Intel-based Mac systems.
- Affected
- Apple Multiple Products
- Required action
- Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
- Due date
- Ransomware use
- Unknown