Junglewise Threat Intelligence

CVE-2024-44309: Apple Multiple Products Cross-Site Scripting (XSS) Vulnerability

CVE-2024-44309 · Severity: critical · CVSS 6.3 · Exploited in the wild · Published 2024-11-21

Technologies: Apple Visionos, Apple macOS Sequoia, Apple Multiple Products, Apple Safari. Vendors: Apple.

Executive brief

A cookie management issue in Apple's WebKit engine allows for cross-site scripting (XSS) when processing maliciously crafted web content. The vulnerability was addressed through improved state management across multiple Apple operating systems.

Affected products

  • Apple Safari < 18.1.1
  • Apple iOS and iPadOS < 17.7.2, 18.0 to < 18.1.1
  • Apple macOS Sequoia 15.0 to < 15.1.1
  • Apple visionOS < 2.1.1

Timeline

  • 2024-11-21: disclosed
  • 2024-11-21: kev added: CISA added to Known Exploited Vulnerabilities catalog.
  • 2024-11-21: exploited: Apple reported awareness of active exploitation on Intel-based Mac systems.
  • 2024-11-21: patched: Fixed in Safari 18.1.1, iOS 17.7.2/18.1.1, macOS 15.1.1, and visionOS 2.1.1.

Related threats