ZeroHour
Help Net Securitypublished ()ingested @zeljkazorz

Apple fixes 2 zero-days exploited to breach macOS systems (CVE-2024-44309, CVE-2024-44308)

criticalVulnerability exploited in the wildimportance 60CVE-2024-44309CVE-2024-44308

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2024-44308
+1 in the same advisory: …44309
Arbitrary Code Execution via Crafted Web Content in Apple Safari, iOS, macOS and visionOS

CVE-2024-44308 is a code execution vulnerability in the web content processing engine used by Safari and Apple's operating systems, which Apple addressed with improved checks in emergency updates released in November 2024. It is triggered when a device processes maliciously crafted web content, for example when a user is lured to an attacker-controlled webpage, and requires user interaction (CVSS 3.1: AV:N/UI:R). Successful exploitation yields arbitrary code execution with high impact on confidentiality, integrity, and availability (CVSS 3.1 score 8.8). Users of Safari before 18.1.1, iOS and iPadOS before 17.7.2 and 18.1.1, macOS Sequoia before 15.1.1, and visionOS before 2.1.1 are affected; Debian Linux is also listed in the CPE data but no Debian-specific fix version was provided in the source. Apple reported active exploitation, specifically on Intel-based Mac systems, and CISA added the flaw to its Known Exploited Vulnerabilities catalog on 2024-11-21; EPSS assigns a 9.4% probability of exploitation within 30 days.

Do: Immediately update to Safari 18.1.1, iOS/iPadOS 17.7.2 or 18.1.1, macOS Sequoia 15.1.1 and visionOS 2.1.1, prioritizing Intel-based Macs since confirmed exploitation was reported on those systems. Federal agencies must patch per CISA's KEV requirement (added 2024-11-21), and defenders should review unpatched Macs for signs of browser-based compromise. Debian users should monitor their vendor's advisory for a WebKit-related backport, as no fixed Debian version was specified in the source data.

8.8
group max
10% KEV
  • Apple Safari versions prior to 18.1.1 (fixed in Safari 18.1.1)
  • Apple iOS (iPhone OS) versions prior to 17.7.2 and prior to 18.1.1 (fixed in iOS 17.7.2 and iOS 18.1.1)
  • Apple iPadOS versions prior to 17.7.2 and prior to 18.1.1 (fixed in iPadOS 17.7.2 and iPadOS 18.1.1)
  • +3 more
masshundreds of millions to 1 billion+ users (Apple's global active device base across iPhone, iPad, Mac, Vision Pro and Safari)
Full article372 words · extracted from helpnetsecurity.com · click to collapse

Apple has released emergency security updates for macOS Sequoia that fix two zero-day vulnerabilities (CVE-2024-44309, CVE-2024-44308) that “may have been actively exploited on Intel-based Mac systems”.

CVE-2024-44309 CVE-2024-44308

About CVE-2024-44309 and CVE-2024-44308

CVE-2024-44309 affects WebKit, the browser engine used in the Safari web browser and all iOS and iPadOS web browsers, and can be triggered when it’s made to process maliciously crafted web content. It can enable a cross site scripting (XSS) attack.

CVE-2024-44308 affects JavaScriptCore – the built-in JavaScript engine for WebKit – and can likewise be exploited via maliciously crafted web content. It can lead to arbitrary code execution.

Both vulnerabilities have been reported by security researchers Clément Lecigne and Benoît Sevens of Google’s Threat Analysis Group (TAG), which aims to protect users from advanced persistent threats such as state-sponsored malware and commercial spyware attacks, as well as financially motivated attacks.

As per usual, Apple didn’t share details about the attacks in which patched vulnerabilities are exploited. Google TAG usually disclosed such details months after the patches are provided.

Still, it’s safe to say that the spotted attacks aren’t indiscriminately targeting all Mac users, but are leveraging the flaws for targeted attacks.

Update ASAP!

Apple has transitioned to using Intel processors on Macs in June 2006 and stopped shipping them altogether in June 2023, after starting using its own silicon in 2020.

The two vulnerabilities “may have been actively exploited on Intel-based Mac systems”, but it’s unclear at this time whether that means that they can’t be exploited on Apple-based Macs.

In any case, all MacOS Sequoia users should update their systems as soon as possible.

While Apple’s mobile devices (iPhones, iPads) and its mixed-reality headset (Vision Pro) don’t run on Intel silicon, CVE-2024-44309 and CVE-2024-44308 have also been fixed in Safari, visionsOS, iOS and iPadOS 18 and 17, to protect iPhone, iPad, Vision Pro and Mac users that use older macOS branches.

UPDATE (November 27, 2024, 01:20 p.m. ET):

The two vulnerabilities have also been fixed in WPE, the official WebKit port for Linux-based embedded devices, and WebKitGTK, a WebKit port for projects requiring web integration.

Subscribe to our breaking news e-mail alert to never miss out on the latest breaches, vulnerabilities and cybersecurity threats. Subscribe here!

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2024/11/20/cve-2024-44309-cve-2024-44308/