Executive brief
A cookie management issue in Apple's WebKit engine allows for cross-site scripting (XSS) when processing maliciously crafted web content. The vulnerability was addressed through improved state management across multiple Apple operating systems.
Affected products
- Apple Safari < 18.1.1
- Apple iOS and iPadOS < 17.7.2, 18.0 to < 18.1.1
- Apple macOS Sequoia 15.0 to < 15.1.1
- Apple visionOS < 2.1.1
Timeline
- 2024-11-21: disclosed
- 2024-11-21: kev added: CISA added to Known Exploited Vulnerabilities catalog.
- 2024-11-21: exploited: Apple reported awareness of active exploitation on Intel-based Mac systems.
- 2024-11-21: patched: Fixed in Safari 18.1.1, iOS 17.7.2/18.1.1, macOS 15.1.1, and visionOS 2.1.1.