ZeroHour

CVE-2024-44309

KEVmass1

Actively Exploited XSS in Apple WebKit Web Content Handling (iOS, iPadOS, macOS)

CISA: Apple Multiple Products Cross-Site Scripting (XSS) Vulnerability

CVSS 3.1
6.3 medium
EPSS
23%p98
Published
()
KEV added
AI analysis

CVE-2024-44309 is a cross-site scripting flaw (CWE-79) in how Apple's WebKit engine processes maliciously crafted web content on iOS, iPadOS, macOS, and other WebKit-based Apple products; Apple's advisories describe it as a cookie-management issue addressed with improved handling. An attacker triggers it by getting a user's browser or an app's embedded web view to load crafted web content, which allows script to run in the context of the targeted site — for example, reading or tampering with cookies and hijacking sessions. Any unpatched iPhone, iPad, or Mac — including users of Safari and third-party apps that render web content via Apple's web views — is in scope, and CISA's affected-product list is broad ('Apple Multiple Products'). The flaw is confirmed exploited in the wild: it was added to CISA's KEV on 2024-11-21 (ransomware use unknown), and EPSS assigns a 22.6% probability of exploitation within 30 days (98th percentile), although no public PoC is known. Fixes shipped in Apple's November 2024 security updates.

What to do: Patch promptly per the KEV-required action: upgrade to iOS/iPadOS 18.1.1 (or iOS/iPadOS 17.7.2 on the 17 branch) and macOS Sequoia 15.1.1, applying the matching Safari/WebKit updates for older macOS versions still in support. Until patched, treat untrusted links opened in Safari or in-app web views on Apple devices as a risk, and use MDM/patch inventories to confirm WebKit updates are installed fleet-wide.

Affected
Apple iOS (WebKit web content processing)Versions prior to iOS 18.1.1, and the iOS 17 branch prior to 17.7.2 (fixed per Apple's November 2024 advisories)
Apple iPadOS (WebKit web content processing)Versions prior to iPadOS 18.1.1, and the iPadOS 17 branch prior to 17.7.2 (fixed per Apple's November 2024 advisories)
Apple macOS (WebKit web content processing)macOS Sequoia versions prior to 15.1.1 (fixed per Apple's November 2024 advisories)
Apple Other WebKit-based Apple products (CISA lists 'Multiple Products'; e.g., Safari and apps embedding Apple web views)
Estimated exposure
mass≈1 billion+ active Apple devices (essentially every iPhone, iPad, and Mac that uses Safari or any app embedding WebKit), of which only unpatched ones are… — Apple has publicly reported an installed base of over 2.2 billion active devices dominated by iOS/iPadOS/macOS, and nearly all of those endpoints render web content through WebKit, so potential exposure is on the order of a billion devices…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A cookie management issue was addressed with improved state management. This issue is fixed in Safari 18.1.1, iOS 17.7.2 and iPadOS 17.7.2, iOS 18.1.1 and iPadOS 18.1.1, macOS Sequoia 15.1.1, visionOS 2.1.1. Processing maliciously crafted web content may lead to a cross site scripting attack. Apple is aware of a report that this issue may have been actively exploited on Intel-based Mac systems.

CISA Known Exploited Vulnerability
Affected
Apple Multiple Products
Required action
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Due date
Ransomware use
Unknown
Vendors
debianapple
Products
debian linux, safari, ipados, iphone os, macos, visionos
Weakness
CWE-79
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L

In the news