Apple Urgently Patches Actively Exploited Zero-Days

  /     /     /  
Publicated : 23/11/2024   Category : security


Apple Urgently Patches Actively Exploited Zero-Days


Though information regarding the exploits is limited, the company did report that Intel-based Mac systems have been targeted by cybercriminals looking to exploit CVE-2024-44308 and CVE-2024-44309.



Apple has released security updates to address two
zero-day vulnerabilities
that are under active exploitation in the wild.
The bugs, tracked as CVE-2024-44308 (CVSS 6.8) and CVE-2024-44309 (CVSS 4.3), are, respectively, a vulnerability in JavaScriptCore that could lead to arbitrary code execution; and a cookie management vulnerability in WebKit that could lead to a
cross-site scripting (XSS) attack
while processing malicious Web content.
The bugs affect Apples iOS, iPadOS, macOS, visionOS, and the Safari Web browser; the company reports that it has addressed them with better checks and improved state management.
Clément Lecigne and Benoît Sevens at Googles Threat Analysis Group (TAG) first discovered and reported the vulnerabilities and, as is customary for the company, Apple did not provide any additional details of reported attacks nor did it offer indicators of compromise (IoCs).
Apple is aware of a report that this issue may have been actively exploited on Intel-based Mac systems, Apple stated its
advisory
for both zero-days, the lone piece of information regarding in-the-wild exploitation attempts.
Those using affected Apple ecosystem products should update to iOS 18.1.1, macOS Sequoia 15.1.1, and  iOS 17.7.2 as soon as possible to avoid compromise.

Last News

▸ DHS-funded SWAMP scans code for bugs. ◂
Discovered: 23/12/2024
Category: security

▸ Debunking Machine Learning in Security. ◂
Discovered: 23/12/2024
Category: security

▸ Researchers create BlackForest to gather, link threat data. ◂
Discovered: 23/12/2024
Category: security


Cyber Security Categories
Google Dorks Database
Exploits Vulnerability
Exploit Shellcodes

CVE List
Tools/Apps
News/Aarticles

Phishing Database
Deepfake Detection
Trends/Statistics & Live Infos



Tags:
Apple Urgently Patches Actively Exploited Zero-Days