Junglewise Threat Intelligence

CVE-2024-44308: Apple Multiple Products Code Execution Vulnerability

CVE-2024-44308 · Severity: critical · CVSS 8.8 · Exploited in the wild · Published 2024-11-21

Technologies: Apple Safari, Apple Visionos, Apple Multiple Products, Apple iPadOS, Apple macOS Sequoia. Vendors: Apple.

Executive brief

Apple iOS, macOS, and other products contain a vulnerability in web content processing that allows for arbitrary code execution. The issue is addressed with improved checks and has been reported as actively exploited on Intel-based Mac systems.

Affected products

  • Apple Safari before 18.1.1
  • Apple iOS before 17.7.2, 18.0 to 18.1.1
  • Apple iPadOS before 17.7.2, 18.0 to 18.1.1
  • Apple macOS Sequoia before 15.1.1
  • Apple visionOS before 2.1.1

Timeline

  • 2024-11-21: disclosed
  • 2024-11-21: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2024-11-21: patched: Fixed in Safari 18.1.1, iOS 17.7.2/18.1.1, macOS 15.1.1, and visionOS 2.1.1
  • 2024-11-21: exploited: Apple is aware of reports of active exploitation on Intel-based Mac systems.

Related threats