Apple Issues Emergency Security Update for Actively Exploited Flaws
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2024-44308 +1 in the same advisory: …44309 | Arbitrary Code Execution via Crafted Web Content in Apple Safari, iOS, macOS and visionOS CVE-2024-44308 is a code execution vulnerability in the web content processing engine used by Safari and Apple's operating systems, which Apple addressed with improved checks in emergency updates released in November 2024. It is triggered when a device processes maliciously crafted web content, for example when a user is lured to an attacker-controlled webpage, and requires user interaction (CVSS 3.1: AV:N/UI:R). Successful exploitation yields arbitrary code execution with high impact on confidentiality, integrity, and availability (CVSS 3.1 score 8.8). Users of Safari before 18.1.1, iOS and iPadOS before 17.7.2 and 18.1.1, macOS Sequoia before 15.1.1, and visionOS before 2.1.1 are affected; Debian Linux is also listed in the CPE data but no Debian-specific fix version was provided in the source. Apple reported active exploitation, specifically on Intel-based Mac systems, and CISA added the flaw to its Known Exploited Vulnerabilities catalog on 2024-11-21; EPSS assigns a 9.4% probability of exploitation within 30 days. Do: Immediately update to Safari 18.1.1, iOS/iPadOS 17.7.2 or 18.1.1, macOS Sequoia 15.1.1 and visionOS 2.1.1, prioritizing Intel-based Macs since confirmed exploitation was reported on those systems. Federal agencies must patch per CISA's KEV requirement (added 2024-11-21), and defenders should review unpatched Macs for signs of browser-based compromise. Debian users should monitor their vendor's advisory for a WebKit-related backport, as no fixed Debian version was specified in the source data. | 8.8 group max | 10% | KEV |
| masshundreds of millions to 1 billion+ users (Apple's global active device base across iPhone, iPad, Mac, Vision Pro and Safari) |
Full article338 words · extracted from infosecurity-magazine.com · click to collapse
Apple has urged customers to apply emergency security updates, which fixes two actively exploited vulnerabilities on its devices.
The fixes are included in the iOS 18.1.1 and iPadOS 18.1.1, Safari 18.1.1, visionOS 2.1.1 and macOS Sequoia 15.1.1 updates, available across a range of Apple devices, including iPhones, iPads, macOS and Apple Vision Pro.
These address two vulnerabilities – CVE-2024-44308 and CVE-2024-44309 – which Apple said may be actively exploited on Intel-based Mac systems. No details have been provided on which threat actors may be involved in this activity.
Both vulnerabilities have been received by the National Vulnerability Database (NVD) but have not yet been analyzed and assigned a score.
Additionally, iOS 17.7.2 and iPadOS 17.7.2 has been released to address the flaws for customers with older devices.
The vulnerabilities were discovered by Clément Lecigne and Benoît Sevens of Google's Threat Analysis Group.
Commenting on the security updates, Michael Covington, VP of Strategy at Jamf, recommended updating any device that is at risk.
“The fixes provided by Apple introduce stronger checks to detect and prevent malicious activity, as well as improve how devices manage and track data during web browsing. With attackers potentially exploiting both vulnerabilities, it is critical that users and mobile-first organizations apply the latest patches as soon as they are able,” he said.
Read now: Apple Rolls Out Major Security Update to Patch macOS and iOS Vulnerabilities
JavaScriptCore Vulnerability
CVE-2024-44308 is a vulnerability in JavaScriptCore, which a framework for running JavaScript code in apps and web browsers.
Apple explained that attackers’ maliciously crafting web content in JavaScriptCore can lead to arbitrary code execution and compromising the device.
Apple said the issue has been addressed in the updates with “improved checks.”
WebKit Vulnerability
CVE-2024-44309 is a flaw found in WebKit, a framework which powers Safari and presents other web-based content to users.
This vulnerability enables cross site scripting attacks by maliciously crafted web content.
Apple described the flaw as a “cookie management issue,” which has been addressed with improved state management.
Image credit: Tada Images / Shutterstock.com
Text extracted automatically; images, tables and formatting may be missing. Original: https://www.infosecurity-magazine.com/news/apple-security-update/