Executive brief
Apple iOS, macOS, and other products contain a vulnerability in web content processing that allows for arbitrary code execution. The issue is addressed with improved checks and has been reported as actively exploited on Intel-based Mac systems.
Affected products
- Apple Safari before 18.1.1
- Apple iOS before 17.7.2, 18.0 to 18.1.1
- Apple iPadOS before 17.7.2, 18.0 to 18.1.1
- Apple macOS Sequoia before 15.1.1
- Apple visionOS before 2.1.1
Timeline
- 2024-11-21: disclosed
- 2024-11-21: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2024-11-21: patched: Fixed in Safari 18.1.1, iOS 17.7.2/18.1.1, macOS 15.1.1, and visionOS 2.1.1
- 2024-11-21: exploited: Apple is aware of reports of active exploitation on Intel-based Mac systems.